OESA-2023-1420

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2023-1420
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2023-1420.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2023-1420
Upstream
Published
2023-07-08T11:05:31Z
Modified
2025-08-12T05:20:12.172310Z
Summary
perl-CPAN security update
Details

The CPAN module automates or at least simplifies the make and install of perl modules and extensions. It includes some primitive searching capabilities and knows how to use LWP, HTTP::Tiny, Net::FTP and certain external download clients to fetch distributions from the net. The CPAN module also supports named and versioned bundles of modules. Bundles simplify handling of sets of related modules.

Security Fix(es):

CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.(CVE-2023-31484)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP1 / perl-CPAN

Package

Name
perl-CPAN
Purl
pkg:rpm/openEuler/perl-CPAN&distro=openEuler-20.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.27-4.oe1

Ecosystem specific

{
    "src": [
        "perl-CPAN-2.27-4.oe1.src.rpm"
    ],
    "noarch": [
        "perl-CPAN-help-2.27-4.oe1.noarch.rpm",
        "perl-CPAN-2.27-4.oe1.noarch.rpm"
    ]
}

openEuler:20.03-LTS-SP3 / perl-CPAN

Package

Name
perl-CPAN
Purl
pkg:rpm/openEuler/perl-CPAN&distro=openEuler-20.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.27-4.oe1

Ecosystem specific

{
    "src": [
        "perl-CPAN-2.27-4.oe1.src.rpm"
    ],
    "noarch": [
        "perl-CPAN-help-2.27-4.oe1.noarch.rpm",
        "perl-CPAN-2.27-4.oe1.noarch.rpm"
    ]
}

openEuler:22.03-LTS / perl-CPAN

Package

Name
perl-CPAN
Purl
pkg:rpm/openEuler/perl-CPAN&distro=openEuler-22.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.29-2.oe2203sp2

Ecosystem specific

{
    "src": [
        "perl-CPAN-2.29-2.oe2203.src.rpm",
        "perl-CPAN-2.29-2.oe2203sp1.src.rpm",
        "perl-CPAN-2.29-2.oe2203sp2.src.rpm"
    ],
    "noarch": [
        "perl-CPAN-2.29-2.oe2203.noarch.rpm",
        "perl-CPAN-help-2.29-2.oe2203.noarch.rpm",
        "perl-CPAN-2.29-2.oe2203sp1.noarch.rpm",
        "perl-CPAN-help-2.29-2.oe2203sp1.noarch.rpm",
        "perl-CPAN-help-2.29-2.oe2203sp2.noarch.rpm",
        "perl-CPAN-2.29-2.oe2203sp2.noarch.rpm"
    ]
}

openEuler:22.03-LTS-SP1 / perl-CPAN

Package

Name
perl-CPAN
Purl
pkg:rpm/openEuler/perl-CPAN&distro=openEuler-22.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.29-2.oe2203sp1

Ecosystem specific

{
    "src": [
        "perl-CPAN-2.29-2.oe2203sp1.src.rpm"
    ],
    "noarch": [
        "perl-CPAN-2.29-2.oe2203sp1.noarch.rpm",
        "perl-CPAN-help-2.29-2.oe2203sp1.noarch.rpm"
    ]
}

openEuler:22.03-LTS-SP2 / perl-CPAN

Package

Name
perl-CPAN
Purl
pkg:rpm/openEuler/perl-CPAN&distro=openEuler-22.03-LTS-SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.29-2.oe2203sp2

Ecosystem specific

{
    "src": [
        "perl-CPAN-2.29-2.oe2203sp2.src.rpm"
    ],
    "noarch": [
        "perl-CPAN-help-2.29-2.oe2203sp2.noarch.rpm",
        "perl-CPAN-2.29-2.oe2203sp2.noarch.rpm"
    ]
}