perl: arbitrary command execution
| Package(s): | perl |
CVE #(s): | CVE-2011-1487
|
| Created: | April 25, 2011 |
Updated: | June 21, 2011 |
| Description: |
From the Red Hat bugzilla:
A security flaw was found in the way Perl performed
laundering of tainted data. A remote attacker could
use this flaw to bypass Perl TAINT mode protection
mechanism (leading to commands execution on dirty
arguments or file system access via contaminated
variables) via specially-crafted input provided
to the web application / CGI script.
|
| Alerts: |
| Gentoo |
201311-17 |
perl |
2013-11-28 |
| Debian |
DSA-2265-1 |
perl |
2011-06-20 |
| Pardus |
2011-72 |
perl |
2011-05-02 |
| Ubuntu |
USN-1129-1 |
perl |
2011-05-03 |
| Red Hat |
RHSA-2011:0558-01 |
perl |
2011-05-19 |
| Fedora |
FEDORA-2011-4918 |
perl |
2011-04-06 |
| SUSE |
SUSE-SR:2011:009 |
mailman, openssl, tgt, rsync, vsftpd, libzip1/libzip-devel, otrs, libtiff, kdelibs4, libwebkit, libpython2_6-1_0, perl, pure-ftpd, collectd, vino, aaa_base, exim |
2011-05-17 |
| openSUSE |
openSUSE-SU-2011:0479-1 |
perl |
2011-05-13 |
| Mandriva |
MDVSA-2011:091 |
perl |
2011-05-18 |
|