|
|
| |
|
| |
perl: arbitrary command execution
| Package(s): | perl |
CVE #(s): | CVE-2011-1487
|
| Created: | April 25, 2011 |
Updated: | June 21, 2011 |
| Description: |
From the Red Hat bugzilla:
A security flaw was found in the way Perl performed
laundering of tainted data. A remote attacker could
use this flaw to bypass Perl TAINT mode protection
mechanism (leading to commands execution on dirty
arguments or file system access via contaminated
variables) via specially-crafted input provided
to the web application / CGI script.
|
| Alerts: |
|
( Log in to post comments)
|
|
|