ELA-1755-1 libhttp-daemon-perl security update

execution of arbitrary commands or file overwrite

2026-06-23
Packagelibhttp-daemon-perl
Version6.01-1+deb9u2 (stretch), 6.01-3+deb10u2 (buster)
Related CVEs CVE-2026-8450


A flaw was discovered in libhttp-daemon-perl, a simple http server class for Perl, which may result in the execution of arbitrary shell commands or file overwrite when processing specially crafted input.



For Debian 10 buster, these problems have been fixed in version 6.01-3+deb10u2.

For Debian 9 stretch, these problems have been fixed in version 6.01-1+deb9u2.

We recommend that you upgrade your libhttp-daemon-perl packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.