UbuntuUpdates.org

Package "libhttp-daemon-perl"

Name: libhttp-daemon-perl

Description:

simple http server class

Latest version: 6.16-1ubuntu0.26.04.1
Release: resolute (26.04)
Level: updates
Repository: main
Homepage: https://metacpan.org/release/HTTP-Daemon

Links


Download "libhttp-daemon-perl"


Other versions of "libhttp-daemon-perl" in Resolute

Repository Area Version
base main 6.16-1
security main 6.16-1ubuntu0.26.04.1

Changelog

Version: 6.16-1ubuntu0.26.04.1 2026-06-10 19:07:39 UTC

  libhttp-daemon-perl (6.16-1ubuntu0.26.04.1) resolute-security; urgency=medium

  * SECURITY UPDATE: Remote code execution via send_file.
    - debian/patches/CVE-2026-8450.patch: Change open to 3 args and add 0E0
      with return in lib/HTTP/Daemon.pm.
    - CVE-2026-8450

 -- Hlib Korzhynskyy <email address hidden> Tue, 09 Jun 2026 17:35:43 -0230

CVE-2026-8450 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(



About   -   Send Feedback to @ubuntu_updates