Since CERT-FI hasn't mentioned perl, no perl XML tools are vulnerable, maybe :) who knows? probably the same vulnerabilities exist | [reply] [Watch: Dir/Any] [d/l] |
The report indicates vulnerabilities for:
- python with libexpat
- xerces
- sun jre builtin xml parser
AFAIK, of these, only libexpat is widely used in Perl. If your code makes use of XML::Parser, you probably have the same vulnerability.
The main alternative, XML::LibXML, is based on libxml2, which was not mentioned in the report, so it might be safe.
| [reply] [Watch: Dir/Any] |
The CERT report does cite libxml2 now as well, so this seems to be a very pervasive issue.
Patches for libxml2 can be found in this Bugzilla ticket against 2.5.10, 2.6.16, and 2.6.26. It does not appear that this fix has been rolled into an official release yet.
| [reply] [Watch: Dir/Any] |
| [reply] [Watch: Dir/Any] |