Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-10224

Опубликовано: 19 нояб. 2024
Источник: redhat
CVSS3: 5.3

Описание

Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute arbitrary shell commands by open()ing a "pesky pipe" (such as passing "commands|" as a filename) or by passing arbitrary strings to eval().

A flaw was found in the Module-ScanDeps package. Due to the handling of unsanitized input, a local attacker can execute arbitrary shell commands or potentially escalate privileges on the host.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7perl-Module-ScanDepsOut of support scope
Red Hat Enterprise Linux 8perl-Module-ScanDepsWill not fix
Red Hat Enterprise Linux 9perl-Module-ScanDepsFixedRHSA-2025:735013.05.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2327329module-scandeps: local privilege escalation via unsanitized input

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
9 месяцев назад

Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute arbitrary shell commands by open()ing a "pesky pipe" (such as passing "commands|" as a filename) or by passing arbitrary strings to eval().

CVSS3: 5.3
nvd
9 месяцев назад

Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute arbitrary shell commands by open()ing a "pesky pipe" (such as passing "commands|" as a filename) or by passing arbitrary strings to eval().

CVSS3: 5.3
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 5.3
debian
9 месяцев назад

Qualys discovered that if unsanitized input was used with the library ...

oracle-oval
3 месяца назад

ELSA-2025-7350: perl-Module-ScanDeps security update (MODERATE)

5.3 Medium

CVSS3