CPANSA-Module-ScanDeps-2024-10224: Module-ScanDeps vulnerability
Publisher | giterlizzi | Document category | csaf_security_advisory |
---|---|---|---|
Initial release date | 2024-11-19T00:00:00 | Engine | CSAF Perl Toolkit 0.25 |
Current release date | 2024-11-19T00:00:00 | Build Date | |
Current version | 1 | Status | final |
CVSS v3.1 Base Score | 5.3 | Severity | |
Original language | Language | en | |
Also referred to |
Vulnerability Description
Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute arbitrary shell commands by open()ing a "pesky pipe" (such as passing "commands|" as a filename) or by passing arbitrary strings to eval().
Vulnerabilities
CVE-2024-10224
Vulnerability DescriptionQualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute arbitrary shell commands by open()ing a "pesky pipe" (such as passing "commands|" as a filename) or by passing arbitrary strings to eval().
Weakness | CWE-78 : Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') |
---|
Product status
Known affected
Product | Score | ||||||||
---|---|---|---|---|---|---|---|---|---|
Module-ScanDeps less than 1.36 |
|
Fixed
- Module-ScanDeps greater than or equal 1.36
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-Module-ScanDeps-2024-10224 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2024/cpansa-module-scandeps-2024-10224.json - https://github.com/rschupp/Module-ScanDeps/security/advisories/GHSA-g597-359q-v529 external
https://github.com/rschupp/Module-ScanDeps/security/advisories/GHSA-g597-359q-v529 - https://www.cve.org/CVERecord?id=CVE-2024-10224 external
https://www.cve.org/CVERecord?id=CVE-2024-10224 - https://www.qualys.com/2024/11/19/needrestart/needrestart.txt external
https://www.qualys.com/2024/11/19/needrestart/needrestart.txt - https://lists.debian.org/debian-lts-announce/2024/11/msg00015.html external
https://lists.debian.org/debian-lts-announce/2024/11/msg00015.html - https://ubuntu.com/security/CVE-2024-10224 external
https://ubuntu.com/security/CVE-2024-10224 - CVE-2024-10224 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2024-10224
Revision history
Version | Date of the revision | Summary of the revision |
---|---|---|
1 | Tue Nov 19 00:00:00 2024 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/