TEMP-0000000-F41FA7

NameTEMP-0000000-F41FA7
DescriptionDoS
SourceAutomatically generated temporary name. Not for external reference.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libemail-address-perl (PTS)wheezy, wheezy (security)1.895-1+deb7u1vulnerable
jessie1.905-2vulnerable
buster, sid, stretch1.908-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libemail-address-perlsource(unstable)1.908-1
libemail-address-perlsourcesqueeze1.889-2+deb6u2

Notes

[jessie] - libemail-address-perl <ignored> (Minor issue vs. usability impact of module)
[wheezy] - libemail-address-perl <ignored> (Minor issue vs. usability impact of module)
workaround entry for DLA-320-1 until/if CVE assigned
For the denial of service issue as of 1.908 as mitigation default value
for nestable comments set to deep level 1.
https://github.com/rjbs/Email-Address/commit/3056b7da4fffbce9ad92f9799fffc587ab40303d
No CVE will be assigned for behaviour change between 1.907 and 1.908
See CVE-2015-7686 for the underlying CWE-407 ("Algorithmic Complexity")
issue still present in 1.908
http://www.openwall.com/lists/oss-security/2015/10/02/13

Search for package or bug name: Reporting problems