Bug#887536: dh-make-perl depends on libemail-address-perl

gregor herrmann gregoa at debian.org
Sat May 19 14:28:14 BST 2018


On Wed, 17 Jan 2018 20:50:05 +0100, Pali Rohár wrote:

> Hi! Package dh-make-perl depends on libemail-address-perl which is
> vulnerable to CVE-2015-7686, see bug #868170. libemail-address-perl
> provides perl module Email::Address which is now unmaintained. There is
> a new perl module Email::Address::XS which is API compatible replacement
> for Email::Address and is available in libemail-address-xs-perl. Please
> port dh-make-perl package to use libemail-address-xs-perl. 

dh-make-perl uses

% grep -r Email::Address
Build.PL:        'Email::Address'            => 0,
lib/DhMakePerl/Command/Packaging.pm:use Email::Address;
lib/DhMakePerl/Command/Packaging.pm:my $EMAIL_RE = $Email::Address::addr_spec;

And I think there is no ::addr_spec in libemail-address-xs-perl?

> If you need
> help with porting let me know.
> 
Yes, please :)


Cheers,
gregor

-- 
 .''`.  https://info.comodo.priv.at -- Debian Developer https://www.debian.org
 : :' : OpenPGP fingerprint D1E1 316E 93A7 60A8 104D  85FA BB3A 6801 8649 AA06
 `. `'  Member VIBE!AT & SPI Inc. -- Supporter Free Software Foundation Europe
   `-   
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 963 bytes
Desc: Digital Signature
URL: <http://alioth-lists.debian.net/pipermail/pkg-perl-maintainers/attachments/20180519/dd9fb0fb/attachment.sig>


More information about the pkg-perl-maintainers mailing list