[CLSA-2026:1777548161] Fix CVE(s): CVE-2023-31486
Type:
security
Severity:
Important
Release date:
2026-04-30 11:22:47 UTC
Description:
* SECURITY UPDATE: HTTP::Tiny does not verify TLS certificates by default - debian/patches/CVE-2023-31486.patch: flip verify_SSL default from 0 to 1 in cpan/HTTP-Tiny/lib/HTTP/Tiny.pm; add PERL_HTTP_TINY_SSL_INSECURE_BY_DEFAULT escape-hatch env var; update POD (SSL SUPPORT -> TLS/SSL SUPPORT, machine-in-the-middle, extra CA search paths); add offline regression test cpan/HTTP-Tiny/t/180_verify_SSL.t. - CVE-2023-31486
Updated packages:
  • libperl-dev_5.30.0-9ubuntu0.5+tuxcare.els1_amd64.deb
    sha:6b9cf28724c470cc95606c30242cff95b7f5a775
  • libperl5.30_5.30.0-9ubuntu0.5+tuxcare.els1_amd64.deb
    sha:17fc7c2772ca3d1c9ca409c83bbef1131e07dccc
  • perl_5.30.0-9ubuntu0.5+tuxcare.els1_amd64.deb
    sha:9b429f2d11dcadf2c77b34bfd34f1e63dfbe390e
  • perl-base_5.30.0-9ubuntu0.5+tuxcare.els1_amd64.deb
    sha:46fb604e6d59948a28b2ba61e62bf132ef1c8041
  • perl-debug_5.30.0-9ubuntu0.5+tuxcare.els1_amd64.deb
    sha:b8ba9fad680ba5c44f97f23e1fb65892feb347df
  • perl-doc_5.30.0-9ubuntu0.5+tuxcare.els1_all.deb
    sha:1264a6cf459944b457063177316add40cd95138d
  • perl-modules-5.30_5.30.0-9ubuntu0.5+tuxcare.els1_all.deb
    sha:1ff6c60bb469e93ff424ed9b809efb111465f459
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.