СloudLinux Blog

CloudLinux OS 6 ELS: perl package with the fix for the CVE-2020-10543 and the CVE-2020-10878 gradual rollout

Written by Inessa Atmachian | Aug 3, 2021 7:00:29 AM

A new updated perl package with the fix for the CVE-2020-10543 and the CVE-2020-10878 within CloudLinux OS 6 ELS has been scheduled for gradual rollout from our production repository.

Rollout slot: 3
Rolled out to: 1%
ETA for 100% rollout: August 12

Changelog

perl-5.10.1-146.cloudlinux.els

  • CVE-2020-10543: fix signed integer overflow leading to heap buffer overrun
  • CVE-2020-10878: fix integer overflow leading to RCE

Update command

yum update perl*

Immediate update (via bypass)

yum update perl* --enablerepo=cloudlinux-rollout-3-bypass