Bug#868170: libemail-address-perl: Email::Address->parse() is vulnerable to CVE-2015-7686

Pali Rohár pali.rohar at gmail.com
Thu Nov 23 09:10:56 UTC 2017


On Friday 17 November 2017 23:42:19 Moritz Muehlenhoff wrote:
> On Fri, Nov 17, 2017 at 09:36:46PM +0100, Pali Rohár wrote:
> > On Friday 17 November 2017 12:36:54 Moritz Muehlenhoff wrote:
> > > On Fri, Nov 17, 2017 at 12:03:26PM +0100, Pali Rohár wrote:
> > > > What
> > > > about next, do you have some script or any other tool which can create
> > > > those wishlist bugs for all packages which depend on
> > > > libemail-address-perl package?
> > > 
> > > There's a mass-bug script in 'devscripts", but since there's less than
> > > 20 packages you could also simply file these manually.
> > 
> > Will you or any other maintainer of perl packages do that?
> 
> Anyone can file bugs in the Debian BTS, so why not do it yourself?

Is there some web or dist-independent tool which provides list of all
packages which currently depends on another (libemail-address-perl),
plus to see list of transitive dependency to compare them?

I know just apt rdepends which need to be called on sid (to have current
list of sid packages), but I do not know anything which show transitive
rdepends.

-- 
Pali Rohár
pali.rohar at gmail.com



More information about the pkg-perl-maintainers mailing list