{"id":"MGASA-2025-0276","summary":"Updated perl-CPAN & perl-HTTP-Tiny packages fix security vulnerabilities","details":"CPAN.pm before 2.35 does not verify TLS certificates when downloading\ndistributions over HTTPS. (CVE-2023-31484)\nHTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available\nstandalone on CPAN, has an insecure default TLS configuration where\nusers must opt in to verify certificates. (CVE-2023-31486)\n","modified":"2026-04-16T04:43:38.312135625Z","published":"2025-11-12T21:29:34Z","upstream":["CVE-2023-31484","CVE-2023-31486"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2025-0276.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=31852"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2023/04/29/1"}],"affected":[{"package":{"name":"perl-CPAN","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/perl-CPAN?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.340.0-1.1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2025-0276.json"}},{"package":{"name":"perl-HTTP-Tiny","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/perl-HTTP-Tiny?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.82.0-1.1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2025-0276.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}