LWN.net Logo

perl: arbitrary command execution

Package(s):perl CVE #(s):CVE-2011-1487
Created:April 25, 2011 Updated:June 21, 2011
Description: From the Red Hat bugzilla:

A security flaw was found in the way Perl performed laundering of tainted data. A remote attacker could use this flaw to bypass Perl TAINT mode protection mechanism (leading to commands execution on dirty arguments or file system access via contaminated variables) via specially-crafted input provided to the web application / CGI script.

Alerts:
Debian DSA-2265-1 2011-06-20
Pardus 2011-72 2011-05-02
Ubuntu USN-1129-1 2011-05-03
Red Hat RHSA-2011:0558-01 2011-05-19
Fedora FEDORA-2011-4918 2011-04-06
SUSE SUSE-SR:2011:009 2011-05-17
openSUSE openSUSE-SU-2011:0479-1 2011-05-13
Mandriva MDVSA-2011:091 2011-05-18

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds