Use perl5144delta to Audit a Perl 5.14.4 Upgrade
You will finish with a small, repeatable review of the changes between Perl 5.14.3 and 5.14.4, using the perl5144delta manual page installed by the Debian or Ubuntu perl-doc package. The review identifies the release's security fixes, module changes and VMS-specific correction without pretending that this document upgrades Perl for you.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow 10 to 15 minutes. You need a shell and the perl-doc package. The commands below are read-only and do not need elevated privileges. Do not remove an older Perl, replace a system interpreter or restart an application as part of this review.
1. Confirm which Perl and document you are reviewing
Start by recording the interpreter and the manual page selected by your PATH and man database:
$ perl -e 'printf "%vd\n", $^V'
v5.38.2
$ man -w perl5144delta
/usr/share/man/man1/perl5144delta.1.gz
$ dpkg-query -W -f='${Package} ${Version}\n' perl-doc
perl-doc 5.38.2-3.2ubuntu0.6
The exact package version will differ on another machine. On this host, the installed interpreter is Perl 5.38.2, while the manual page describes the historical 5.14.4 release. That distinction is the first checkpoint: perl5144delta is release documentation, not a report that your running interpreter is 5.14.4.
If man -w reports no file, install the documentation package through your normal package-management process, then repeat the command. Installation changes system state and may require administrative privileges, so it is deliberately outside this read-only audit.
2. Read the release boundary before the details
Display the opening section and confirm exactly what the document compares:
$ man perl5144delta | sed -n '1,24p'
PERL5144DELTA(1) Perl Programmers Reference Guide PERL5144DELTA(1)
NAME
perl5144delta - what is new for perl v5.14.4
DESCRIPTION
This document describes differences between the 5.14.3 release and the
5.14.4 release.
The page also says that an upgrade from an earlier line, such as 5.12.0, should begin with perl5140delta. Do not use this page as a complete cross-version audit when your starting point is earlier than 5.14.3. Record the actual old and new versions in your change ticket, then select every intervening delta document that applies.
3. Extract the security fixes into your upgrade notes
Search the rendered page for the security section and its named issues:
$ man perl5144delta | grep -E 'Security|CVE-|memory leak|buffer-overflow|use-after-free|wrap-around'
Security
CVE-2013-1667: memory exhaustion with arbitrary hash keys
memory leak in Encode
[perl #111594] Socket::unpack_sockaddr_un heap-buffer-overflow
[perl #111586] SDBM_File: fix off-by-one access to global ".dir"
[perl #115992] PL_eval_start use-after-free
wrap-around with IO on long strings
In the notes, link each issue to the component or workload it affects. The most operationally significant entry is CVE-2013-1667: crafted hash keys, such as keys derived from URL arguments, could consume memory and CPU and cause denial of service. The page records that it is fixed in 5.14.4. The other entries include an Encode memory leak, unsafe buffer handling in Socket, an off-by-one access in SDBM_File, a List::Util off-by-two error, debugging-build regex trouble, an eval-related use-after-free and integer wrap-around for strings larger than 2**31 bytes.
Checkpoint: your review notes should contain the release pair, the CVE, the affected modules and the large-string IO issue. Do not infer that every Perl program is exposed to every item. Map the notes to the modules and input paths your application actually uses, then test the application with the fixed interpreter.
4. Check modules and compatibility claims
Inspect the module section rather than assuming that a patch release adds features:
$ man perl5144delta | sed -n '/Modules and Pragmata/,/Documentation/p'
Modules and Pragmata
New Modules and Pragmata
None
Updated Modules and Pragmata
Socket
SDBM_File
List::Util
Encode has been upgraded from version 2.42_01 to version 2.42_02.
Module::CoreList has been updated to version 2.49_06
Removed Modules and Pragmata
None.
The release notes say that the versions of Socket, SDBM_File and List::Util did not change, despite receiving the listed fixes. Encode and Module::CoreList have explicit version updates. That makes this a useful dependency audit, but not a substitute for checking the package's actual files and the application's lock or deployment data.
The same page reports no intentional incompatible changes, no new deprecations, no new diagnostics, no utility changes and no configuration or compilation changes. Treat these as claims about the 5.14.4 release notes, not permission to skip your normal test suite.
5. Handle the platform-specific note
If the target is VMS, include the platform note in the release plan. Perl 5.14.3 failed to compile there when two configuration features were used together: userelocatableinc and usesitecustomize. The page says that this was corrected in 5.14.4 and that other platforms were not affected.
For Linux, mark this item as not applicable rather than treating it as a Linux build fix. The manual page also says there are no new or discontinued platforms and no known problems for this release. Those statements narrow the scope of your review; they do not verify that your local compiler, operating system or packaging pipeline can build Perl.
6. Preserve the audit trail
Save the rendered output and the package version with your change record if your process requires evidence:
$ man perl5144delta > /tmp/perl5144delta-review.txt
$ sha256sum /tmp/perl5144delta-review.txt
$ wc -l /tmp/perl5144delta-review.txt
105 /tmp/perl5144delta-review.txt
The line count is an example from this installed manual and may change with formatter or package revisions. The hash is the useful evidence for a later comparison. The temporary file is safe to remove after the record is stored:
$ rm /tmp/perl5144delta-review.txt
This is the only state-changing command in the guide, and it removes only the temporary review copy. If you need it later, rerun the preceding man command. Never use a broad temporary-directory wildcard for cleanup.
Done means
- You recorded the installed Perl and
perl-docversions separately from the historical 5.14.4 subject. - You confirmed that the comparison is 5.14.3 to 5.14.4, or selected earlier delta pages for an older starting point.
- Your notes cover CVE-2013-1667, the affected modules and the large-string IO fix.
- You checked the explicit module version changes and did not mistake the page for an upgrade tool.
- You classified the VMS compiler correction separately from Linux behaviour.
- You ran application tests before deploying a Perl change.