Skip to content

Conversation

jlsec-bot
Copy link
Contributor

This action searched perl:perl, checking 52 (+6) advisories from NVD and 7 (+13) from EUVD for advisories that pertain here. It identified 5 advisories as being related to the Julia package(s): Perl_jll.

3 advisories apply to all registered versions of a package

These advisories had no obvious failures but computed a range without bounds.

  • CVE-2023-31484 for packages: Perl_jll
    • Perl_jll computed ["*"]. Its latest version (5.34.1+0) has components: {"perl:xml-namespacesupport" = "1.12", "perl:file-which" = "1.27", "perl:getopt-tabular" = "0.3", "perl:regexp-common" = "2017060201", "perl:json" = "4.03", "perl:xml-sax" = ["1.02", "Base-1.09"], "perl:term-readline-gnu" = "1.42", "perl:xml-writer" = "0.900", "perl:exporter-lite" = "0.08", perl = "5.34.1", "perl:term-readkey" = "2.38"}
      • perl:perl at < 5.38.0 includes all versions
  • CVE-2023-31486 for packages: Perl_jll
    • Perl_jll computed ["*"]. Its latest version (5.34.1+0) has components: {"perl:xml-namespacesupport" = "1.12", "perl:file-which" = "1.27", "perl:getopt-tabular" = "0.3", "perl:regexp-common" = "2017060201", "perl:json" = "4.03", "perl:xml-sax" = ["1.02", "Base-1.09"], "perl:term-readline-gnu" = "1.42", "perl:xml-writer" = "0.900", "perl:exporter-lite" = "0.08", perl = "5.34.1", "perl:term-readkey" = "2.38"}
      • perl:perl at < 5.38.0 includes all versions
  • CVE-2023-47038 for packages: Perl_jll
    • Perl_jll computed ["*"]. Its latest version (5.34.1+0) has components: {"perl:xml-namespacesupport" = "1.12", "perl:file-which" = "1.27", "perl:getopt-tabular" = "0.3", "perl:regexp-common" = "2017060201", "perl:json" = "4.03", "perl:xml-sax" = ["1.02", "Base-1.09"], "perl:term-readline-gnu" = "1.42", "perl:xml-writer" = "0.900", "perl:exporter-lite" = "0.08", perl = "5.34.1", "perl:term-readkey" = "2.38"}
      • perl:perl at >= 5.30.0, <= 5.38.0 includes all versions

1 advisories apply to the latest version of a package and do not have a patch

  • CVE-2024-56406 for packages: Perl_jll
    • Perl_jll computed [">= 5.34.0+0"]. Its latest version (5.34.1+0) has components: {"perl:xml-namespacesupport" = "1.12", "perl:file-which" = "1.27", "perl:getopt-tabular" = "0.3", "perl:regexp-common" = "2017060201", "perl:json" = "4.03", "perl:xml-sax" = ["1.02", "Base-1.09"], "perl:term-readline-gnu" = "1.42", "perl:xml-writer" = "0.900", "perl:exporter-lite" = "0.08", perl = "5.34.1", "perl:term-readkey" = "2.38"}
      • perl:perl at >= 5.33.1, < 5.38.4 mapped to [>= 5.34.0+0], includes the latest version`

1 advisories found concrete vulnerable ranges

  • CVE-2023-47039 for packages: Perl_jll
    • Perl_jll computed ["< 5.34.0+0"]. Its latest version (5.34.1+0) has components: {"perl:xml-namespacesupport" = "1.12", "perl:file-which" = "1.27", "perl:getopt-tabular" = "0.3", "perl:regexp-common" = "2017060201", "perl:json" = "4.03", "perl:xml-sax" = ["1.02", "Base-1.09"], "perl:term-readline-gnu" = "1.42", "perl:xml-writer" = "0.900", "perl:exporter-lite" = "0.08", perl = "5.34.1", "perl:term-readkey" = "2.38"}

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants