Home / Alt manpages / perl5125delta(1)

  • perl5125delta(1)
  • User command
  • linux

Use perl5125delta to Audit a Perl 5.12.5 Upgrade

You will finish with a small, repeatable audit for a Perl 5.12.5 upgrade: the installed interpreter is identified, the historical delta is read locally, and the security and compatibility points are recorded without mistaking an old release note for a description of today's runtime. Allow about 15 minutes. You need a shell, the perl-doc package and permission to read the Perl installation. The checks below are read-only.

1. Establish which Perl you are checking

perl5125delta is documentation, not an upgrade command. It describes the differences between Perl 5.12.4 and 5.12.5. Start by finding the interpreter and recording its version:

$ command -v perl
/usr/bin/perl
$ perl -e 'print "$^V\n"'
v5.38.2

Your output may differ. On this machine the installed interpreter is Perl 5.38.2, while the document concerns the older 5.12.5 release. That distinction is the first checkpoint: the manpage can explain what changed in that historical release, but it does not prove that a modern Perl has the same bundled module versions or the same implementation details.

2. Confirm that the delta document is installed

Use perldoc to locate the source and man to read the rendered document:

$ perldoc -l perl5125delta
/usr/share/perl/5.38/pod/perl5125delta.pod
$ man perl5125delta

If perldoc -l cannot find it, install the distribution's documentation package through your normal package-management process. On this host the package is perl-doc, version 5.38.2-3.2ubuntu0.6. The package version identifies the documentation bundle, not a claim that Perl 5.12.5 is installed.

Checkpoint: inspect the opening lines and confirm that the NAME and DESCRIPTION sections say this is "what is new for perl v5.12.5" and that it compares 5.12.4 with 5.12.5. If you are upgrading from 5.12.3, the document explicitly sends you to perl5124delta first.

3. Extract the security work before reading the smaller fixes

Read the Security section first. The 5.12.5 delta records three corrected issues: an Encode heap overflow on certain input, a File::Glob::bsd_glob memory error when unsupported GLOB_ALTDIRFUNC flags are accepted from an external source, and a heap buffer overrun involving the x string repeat operator. The entries identify CVE-2011-2939, CVE-2011-2728 and CVE-2012-5195 respectively.

These notes describe vulnerabilities fixed in that release. They are not a safe invitation to feed hostile values to an old Perl binary. If an application still runs Perl 5.12, treat the interpreter and its bundled modules as an upgrade decision, not as a place to reproduce a vulnerability. Do not copy an untrusted proof of concept into a production process.

For an audit record, capture the relevant headings without modifying the system:

$ man -P cat perl5125delta | sed -n '/^Security$/,/^Incompatible Changes$/p'

The output should contain the three security headings and should end before Incompatible Changes. A pager is often easier for a human review; the pipeline above is useful when attaching a plain-text check to an upgrade ticket.

4. Check the compatibility boundary

The document reports no changes intentionally incompatible with 5.12.4. That is a narrow statement about the release delta. It does not mean an application can jump from any Perl version without testing, and it does not guarantee that third-party CPAN modules or operating-system libraries will behave identically.

Keep the upgrade review focused on the actual runtime. Record the interpreter's build details and the versions of modules named by the delta:

$ perl -V:version -V:archname
version='5.38.2';
archname='x86_64-linux-gnu-thread-multi';
$ perl -MEncode -MFile::Glob -MModule::CoreList -e 'printf "perl=%vd Encode=%s File::Glob=%s Module::CoreList=%s\n", $^V, $Encode::VERSION, $File::Glob::VERSION, $Module::CoreList::VERSION'
perl=5.38.2 Encode=3.19 File::Glob=1.40 Module::CoreList=5.20231129

These values are current on this machine, not the versions listed in the 5.12.5 notes. The delta says that Encode moved from 2.39 to 2.39_01, File::Glob from 1.07 to 1.07_01, and Module::CoreList to 2.50_02. Treat those as historical checkpoints when examining a 5.12.5 installation, not as commands to force onto a modern system.

5. Verify representative behaviour safely

The release notes also mention fixes to charnames::viacode(0), scalar or void-context split, and the x repeat operator. These short checks do not use hostile sizes or change files:

$ perl -Mcharnames=viacode -e 'my $v = charnames::viacode(0); print defined($v) ? "$v\n" : "undef\n"'
NULL
$ perl -e 'my @x = split /,/, "a,b"; print scalar(@x), " ", join("|", @x), "\n"'
2 a|b
$ perl -e 'my $s = "abc"; print $s x 3, "\n"'
abcabcabc

On this host these checks run under Perl 5.38.2, so they are smoke tests for the installed interpreter, not a reproduction of the 5.12.5 implementation. In particular, do not infer that a passing modern test proves an old embedded or vendor Perl has received every fix.

6. Turn the reading into an upgrade decision

Compare the target runtime with the security section, then test the application's real module set and deployment environment. Include perl -V in the evidence, record whether the target is actually 5.12.5 or another release, and read the preceding delta documents for skipped versions. The manpage also points to Changes for exhaustive history and to perlbug for reporting a suspected core defect; neither command upgrades Perl.

Do not use sudo for these checks. Installation, interpreter replacement and service restarts are separate, potentially disruptive actions. If an upgrade changes a service, keep the old package available according to your distribution's recovery policy and test the service before removing anything. There is no undo operation in perl5125delta because it only reads documentation.

Done means

  • The interpreter path, Perl version and architecture are recorded.
  • perl5125delta is confirmed as the 5.12.4 to 5.12.5 delta.
  • The three security fixes and their CVE identifiers are included in the review.
  • Current module versions are kept separate from the historical 5.12.5 versions.
  • Representative checks passed without feeding hostile input to production or changing system state.
  • Any skipped Perl delta documents and application-level tests are assigned before the upgrade proceeds.