Perl 5 Porters Mailing List Summary: September 18th-24th
Hey everyone,
Following is the p5p (Perl 5 Porters) mailing list summary for the past week.
Enjoy!
September 18th-24th
News and Updates
Perl 5.27.4 is now available!
Perl 5.24.3 is now available!
Perl 5.26.1 is now available!
We are looking for someone willing to help updating CPAN modules in core!
Issues
New Issues
- Perl #131582:
[CVE-2017-12837] Heap overflow in
Perl__to_fold_latin1
when compiling case-insensitive regexp. - Perl #131598:
[CVE-2017-12883] Buffer over-read in
S_grok_bslash_N
. - Perl #131665:
[CVE-2017-12814] Perl
$ENV
Key Stack Buffer Overflow. - Perl #132131:
Missing feature flag
-D_GNU_SOURCE
on Linux/musl. - Perl #132138:
t/run/switches.t
fails under miniperl. - Perl #132139:
make minitest
non-zero error code ignored. - Perl #132141: lvalue return broken in signature.
- Perl #132142:
Bleadperl v5.27.3-34-gf6107ca24b breaks
MLEHMANN/AnyEvent-HTTP-2.23.tar.gz
. - Perl #132145:
POSIX
::localtime
not identical toCORE::localtime
. - Perl #132150:
...
(yada-yada) parsing is inconsistent. - Perl #132153:
perl-5.26.1/
doio.c:1529
: (style) Suspicious condition. - Perl #131582:
[CVE-2017-12837] Heap overflow in
Perl__to_fold_latin1
when compiling case-insensitive regexp. - Perl #131598:
[CVE-2017-12883] Buffer over-read in
S_grok_bslash_N
. - Perl #131665:
[CVE-2017-12814] Perl
$ENV
Key Stack Buffer Overflow.
Resolved Issues
- Perl #131582:
[CVE-2017-12837] Heap overflow in
Perl__to_fold_latin1
when compiling case-insensitive regexp. - Perl #131598:
[CVE-2017-12883] Buffer over-read in
S_grok_bslash_N
. - Perl #131665:
[CVE-2017-12814] Perl
$ENV
Key Stack Buffer Overflow. - Perl #131777: signatures accept fancy assignment operators.
- Perl #132008:
Term::ReadLine generates
empty
&STDERR
files. - Perl #132138:
t/run/switches.t
fails under miniperl.
Suggested Patches
James Keenan provided a patch in Perl #132137 to document miniperl.
James also provided a patch for
Perl #132139
(make minitest
non-zero error code ignored).
A patch by Scott Court for Perl 5.22 for CVE-2017-12883 in Perl #132134.
Nicholas R. (Atoomic) provided a patch, now merged, in
Perl #132123
to add CvGvNAME_HEK
helper.
Nicholas also provided with Todd Rinaldo an updated patch for
Perl #129916:
(CV
symbol table optimization only works in main::
).
Vickenty provided a patch for
Perl #131867
(%{^CAPTURE_ALL}
is %+
, not %-
).
Lukas Mai (mauke) provided a patch for
Perl #132150
(...
(yada-yada) parsing is inconsistent).
It seems like Cent OS 5 can build Perl 5.26.