Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-1437

Опубликовано: 28 янв. 2020
Источник: debian

Описание

Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute arbitrary Perl code via the $Version value.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
perlfixed5.18.1-2package
perlnot-affectedwheezypackage
perlnot-affectedsqueezepackage
libmodule-metadata-perlfixed1.000015-1package
libmodule-metadata-perlfixed1.000009-1+deb7u1wheezypackage

Примечания

  • this is by 'design', but previous to version Module::Metadata 1.000015

  • the statement was This module provides a standard way to gather metadata

  • about a .pm file *without* executing unsafe code.

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 6 лет назад

Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute arbitrary Perl code via the $Version value.

redhat
больше 12 лет назад

Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute arbitrary Perl code via the $Version value.

CVSS3: 9.8
nvd
около 6 лет назад

Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute arbitrary Perl code via the $Version value.

github
почти 4 года назад

Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute arbitrary Perl code via the $Version value.