Re: [Koha] SECURITY release: MARC::File::XML 1.0.2

2014-01-22 Thread Galen Charlton
Hi, On Wed, Jan 22, 2014 at 2:33 PM, David Cook dc...@prosentient.com.au wrote: If/when libmarc-xml-perl gets added to debian.koha-community.org, will Koha users who installed via the Debian packages get the update automatically? As Robin mentioned, the new package is now available. To answer

Re: [Koha] SECURITY release: MARC::File::XML 1.0.2

2014-01-22 Thread David Cook
-List koha@lists.katipo.co.nz Subject: [Koha] SECURITY release: MARC::File::XML 1.0.2 Message-ID: CAPLnt652-mSU3RHD3=zmx7ijaxjmebnjau0ezesymmjvhc2...@mail.gmail.com Content-Type: text/plain; charset=ISO-8859-1 Hi, I have uploaded [1] version 1.0.2 of MARC::File::XML, a Perl module which

Re: [Koha] SECURITY release: MARC::File::XML 1.0.2

2014-01-22 Thread Robin Sheat
Galen Charlton schreef op wo 22-01-2014 om 14:41 [-0800]: To answer your question, in general, no, it wouldn't happen automatically. To upgrade MARC::File::XML from the new package, one would either do: sudo apt-get update sudo apt-get upgrade This is normal practice for ensuring you are

Re: [Koha] SECURITY release: MARC::File::XML 1.0.2

2014-01-22 Thread Paul A
At 10:32 AM 1/21/2014 -0800, Galen Charlton wrote: Hi, I have uploaded [1] version 1.0.2 of MARC::File::XML, a Perl module which is used by Koha. This is a security release that repairs an XML external entity (XXE) vulnerability. [snip] Hi Galen - I've been keeping an eye open for this

Re: [Koha] SECURITY release: MARC::File::XML 1.0.2

2014-01-22 Thread Galen Charlton
Hi, On Wed, Jan 22, 2014 at 3:15 PM, Paul A pau...@navalmarinearchive.com wrote: Could you please advise on 1.0.2 versus 0.92-1 -- the devil is always in the details. All versions of MARC::File::XML prior to 1.0.2 are subject to the vulnerability, including the Debian- and Ubuntu-packaged

Re: [Koha] SECURITY release: MARC::File::XML 1.0.2

2014-01-22 Thread Robin Sheat
Paul A schreef op wo 22-01-2014 om 18:15 [-0500]: me@hardy:/$ sudo apt-cache show libmarc-xml-perl Package: libmarc-xml-perl Version: 1.0.2-1koha1 Architecture: all Maintainer: Robin Sheat ro...@catalyst.net.nz [snip] Package: libmarc-xml-perl Priority: optional Section: universe/perl

Re: [Koha] SECURITY release: MARC::File::XML 1.0.2

2014-01-22 Thread Paul A
At 03:22 PM 1/22/2014 -0800, Galen Charlton wrote: Hi, On Wed, Jan 22, 2014 at 3:15 PM, Paul A pau...@navalmarinearchive.com wrote: Could you please advise on 1.0.2 versus 0.92-1 -- the devil is always in the details. All versions of MARC::File::XML prior to 1.0.2 are subject to the

Re: [Koha] SECURITY release: MARC::File::XML 1.0.2

2014-01-22 Thread Mark Tompsett
Greetings, Paul A. asked Galen: Could you please advise on 1.0.2 versus 0.92-1 -- the devil is always in the details. You should have noted that Galen had previously given a URL: https://metacpan.org/release/GMCHARLT/MARC-XML-1.0.2 Click on the Other files link called Changes for a fuller

Re: [Koha] SECURITY release: MARC::File::XML 1.0.2

2014-01-22 Thread Paul A
At 12:31 PM 1/23/2014 +1300, Robin Sheat wrote: [snip] For checking what is actually installed, you want apt-cache policy, e.g. [snip] The *** indicates that I have 1.0.1 installed, libmarc-xml-perl: Installed: 1.0.2-1koha1 Candidate: 1.0.2-1koha1 Version table: *** 1.0.2-1koha1 0

Re: [Koha] SECURITY release: MARC::File::XML 1.0.2

2014-01-22 Thread Paul A
At 06:32 PM 1/22/2014 -0500, Mark Tompsett wrote: Greetings, Paul A. asked Galen: Could you please advise on 1.0.2 versus 0.92-1 -- the devil is always in the details. You should have noted that Galen had previously given a URL: https://metacpan.org/release/GMCHARLT/MARC-XML-1.0.2 Click

Re: [Koha] SECURITY release: MARC::File::XML 1.0.2

2014-01-21 Thread Robin Sheat
Galen Charlton schreef op di 21-01-2014 om 10:32 [-0800]: I imagine that an updated Debian package of libmarc-xml-perl will be made available on debian.koha-community.org at some point as well. This is available now. -- Robin Sheat Catalyst IT Ltd. ✆ +64 4 803 2204 GPG: 5FA7 4B49 1E4D CAA4