LWN.net Logo

perl: restriction bypass

Package(s):perl CVE #(s):CVE-2010-1168
Created:June 8, 2010 Updated:November 21, 2011
Description: From the Red Hat advisory:

The Safe module did not properly restrict the code of implicitly called methods (such as DESTROY and AUTOLOAD) on implicitly blessed objects returned as a result of unsafe code evaluation. These methods could have been executed unrestricted by Safe when such objects were accessed or destroyed. A specially-crafted Perl script executed inside of a Safe compartment could use this flaw to bypass intended Safe module restrictions.

Alerts:
Gentoo 201111-09 2011-11-20
Ubuntu USN-1129-1 2011-05-03
SUSE SUSE-SR:2010:016 2010-08-26
openSUSE openSUSE-SU-2010:0519-1 2010-08-18
openSUSE openSUSE-SU-2010:0518-1 2010-08-18
Fedora FEDORA-2010-11340 2010-07-23
Fedora FEDORA-2010-11323 2010-07-23
rPath rPSA-2010-0063-1 2010-10-17
Red Hat RHSA-2010:0458-02 2010-06-07
Red Hat RHSA-2010:0457-01 2010-06-07
Mandriva MDVSA-2010:116 2010-06-11
Pardus 2010-88 2010-06-24
Mandriva MDVSA-2010:115 2010-06-11
MeeGo MeeGo-SA-10:07 2010-07-07
CentOS CESA-2010:0458 2010-06-12

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds