CPANSA-Safe-2010-1447: Safe vulnerability
Publisher | giterlizzi | Document category | csaf_security_advisory |
---|---|---|---|
Initial release date | 2010-05-19T00:00:00 | Engine | CSAF Perl Toolkit 0.25 |
Current release date | 2010-05-19T00:00:00 | Build Date | |
Current version | 1 | Status | final |
CVSS v3.1 Base Score | Severity | ||
Original language | Language | en | |
Also referred to |
Vulnerability Description
The Safe (aka Safe.pm) module 2.26, and certain earlier versions, for Perl, as used in PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2, allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving subroutine references and delayed execution.
Vulnerabilities
CVE-2010-1447
Vulnerability DescriptionThe Safe (aka Safe.pm) module 2.26, and certain earlier versions, for Perl, as used in PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2, allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving subroutine references and delayed execution.
Weakness | CWE-264 : Permissions, Privileges, and Access Controls |
---|
Product status
Known affected
Product | Score | ||||||||
---|---|---|---|---|---|---|---|---|---|
Safe less than or equal 2.26 |
|
Fixed
- Safe greater than or equal 2.27
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-Safe-2010-1447 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2010/cpansa-safe-2010-1447.json - https://bugs.launchpad.net/bugs/cve/2010-1447 external
https://bugs.launchpad.net/bugs/cve/2010-1447 - http://www.vupen.com/english/advisories/2010/1167 external
http://www.vupen.com/english/advisories/2010/1167 - http://secunia.com/advisories/39845 external
http://secunia.com/advisories/39845 - http://www.postgresql.org/about/news.1203 external
http://www.postgresql.org/about/news.1203 - http://security-tracker.debian.org/tracker/CVE-2010-1447 external
http://security-tracker.debian.org/tracker/CVE-2010-1447 - https://bugzilla.redhat.com/show_bug.cgi?id=588269 external
https://bugzilla.redhat.com/show_bug.cgi?id=588269 - http://www.securitytracker.com/id?1023988 external
http://www.securitytracker.com/id?1023988 - http://osvdb.org/64756 external
http://osvdb.org/64756 - http://www.securityfocus.com/bid/40305 external
http://www.securityfocus.com/bid/40305 - http://secunia.com/advisories/40052 external
http://secunia.com/advisories/40052 - http://www.redhat.com/support/errata/RHSA-2010-0458.html external
http://www.redhat.com/support/errata/RHSA-2010-0458.html - http://www.openwall.com/lists/oss-security/2010/05/20/5 external
http://www.openwall.com/lists/oss-security/2010/05/20/5 - http://www.mandriva.com/security/advisories?name=MDVSA-2010:116 external
http://www.mandriva.com/security/advisories?name=MDVSA-2010:116 - http://www.redhat.com/support/errata/RHSA-2010-0457.html external
http://www.redhat.com/support/errata/RHSA-2010-0457.html - http://www.mandriva.com/security/advisories?name=MDVSA-2010:115 external
http://www.mandriva.com/security/advisories?name=MDVSA-2010:115 - http://secunia.com/advisories/40049 external
http://secunia.com/advisories/40049 - http://www.debian.org/security/2011/dsa-2267 external
http://www.debian.org/security/2011/dsa-2267 - http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705 external
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7320 external
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7320 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11530 external
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11530 - CVE-2010-1447 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2010-1447
Revision history
Version | Date of the revision | Summary of the revision |
---|---|---|
1 | Wed May 19 00:00:00 2010 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/