CPANSA-Safe-2010-1168: Safe vulnerability
Publisher | giterlizzi | Document category | csaf_security_advisory |
---|---|---|---|
Initial release date | 2010-06-21T00:00:00 | Engine | CSAF Perl Toolkit 0.25 |
Current release date | 2010-06-21T00:00:00 | Build Date | |
Current version | 1 | Status | final |
CVSS v3.1 Base Score | Severity | ||
Original language | Language | en | |
Also referred to |
Vulnerability Description
The Safe (aka Safe.pm) module before 2.25 for Perl allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving implicitly called methods and implicitly blessed objects, as demonstrated by the (a) DESTROY and (b) AUTOLOAD methods, related to "automagic methods."
Vulnerabilities
CVE-2010-1168
Vulnerability DescriptionThe Safe (aka Safe.pm) module before 2.25 for Perl allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving implicitly called methods and implicitly blessed objects, as demonstrated by the (a) DESTROY and (b) AUTOLOAD methods, related to "automagic methods."
Weakness | CWE-264 : Permissions, Privileges, and Access Controls |
---|
Product status
Known affected
Product | Score | ||||||||
---|---|---|---|---|---|---|---|---|---|
Safe less than 2.25 |
|
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-Safe-2010-1168 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2010/cpansa-safe-2010-1168.json - http://www.openwall.com/lists/oss-security/2010/05/20/5 external
http://www.openwall.com/lists/oss-security/2010/05/20/5 - http://www.redhat.com/support/errata/RHSA-2010-0457.html external
http://www.redhat.com/support/errata/RHSA-2010-0457.html - http://www.redhat.com/support/errata/RHSA-2010-0458.html external
http://www.redhat.com/support/errata/RHSA-2010-0458.html - http://secunia.com/advisories/40049 external
http://secunia.com/advisories/40049 - http://cpansearch.perl.org/src/RGARCIA/Safe-2.27/Changes external
http://cpansearch.perl.org/src/RGARCIA/Safe-2.27/Changes - http://www.mandriva.com/security/advisories?name=MDVSA-2010:115 external
http://www.mandriva.com/security/advisories?name=MDVSA-2010:115 - http://blogs.perl.org/users/rafael_garcia-suarez/2010/03/new-safepm-fixes-security-hole.html external
http://blogs.perl.org/users/rafael_garcia-suarez/2010/03/new-safepm-fixes-security-hole.html - http://www.mandriva.com/security/advisories?name=MDVSA-2010:116 external
http://www.mandriva.com/security/advisories?name=MDVSA-2010:116 - https://bugzilla.redhat.com/show_bug.cgi?id=576508 external
https://bugzilla.redhat.com/show_bug.cgi?id=576508 - http://secunia.com/advisories/40052 external
http://secunia.com/advisories/40052 - http://securitytracker.com/id?1024062 external
http://securitytracker.com/id?1024062 - http://secunia.com/advisories/42402 external
http://secunia.com/advisories/42402 - http://blogs.sun.com/security/entry/cve_2010_1168_vulnerability_in external
http://blogs.sun.com/security/entry/cve_2010_1168_vulnerability_in - http://www.vupen.com/english/advisories/2010/3075 external
http://www.vupen.com/english/advisories/2010/3075 - http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735 external
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735 - http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705 external
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9807 external
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9807 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7424 external
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7424 - CVE-2010-1168 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2010-1168
Revision history
Version | Date of the revision | Summary of the revision |
---|---|---|
1 | Mon Jun 21 00:00:00 2010 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/