Security Advisories (4)
CVE-2007-4769 (2008-01-09)

The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated users to cause a denial of service (backend crash) via an out-of-bounds backref number.

CVE-2018-25032 (2022-03-25)

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

CVE-2011-3045 (2012-03-22)

Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.

CVE-2016-10087 (2017-01-30)

The png_set_text_2 function in libpng 0.71 before 1.0.67, 1.2.x before 1.2.57, 1.4.x before 1.4.20, 1.5.x before 1.5.28, and 1.6.x before 1.6.27 allows context-dependent attackers to cause a NULL pointer dereference vectors involving loading a text chunk into a png structure, removing the text, and then adding another text chunk to the structure.

NAME

Tk::Submethods - add aliases for tk sub-commands

SYNOPSIS

use Tk::Submethods ( 'command1' => [qw(sub1 sub2 sub3)],
                     'command2' => [qw(sub1 sub2 sub3)]);

DESCRIPTION

Creates ->commandSub(...) as an alias for ->command('sub',...) e.g. ->grabRelease for ->grab('release').

For each command/subcommand pair this creates a closure with command and subcommand as bound lexical variables and assigns a reference to this to a 'glob' in the callers package.

Someday the sub-commands may be created directly in the C code.