Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-4407

Опубликовано: 23 нояб. 2013
Источник: ubuntu
Приоритет: medium
CVSS2: 6.8

Описание

HTTP::Body::Multipart in the HTTP-Body module for Perl (1.07 through 1.22, before 1.23) uses the part of the uploaded file's name after the first "." character as the suffix of a temporary file, which makes it easier for remote attackers to conduct attacks by leveraging subsequent behavior that may assume the suffix is well-formed.

РелизСтатусПримечание
devel

not-affected

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [1.19-1]]
lucid

ignored

end of life
precise

released

1.11-1+deb7u1build0.12.04.1
trusty

not-affected

1.19-1
trusty/esm

DNE

trusty was not-affected [1.19-1]
upstream

needs-triage

utopic

not-affected

vivid

not-affected

Показывать по

Ссылки на источники

6.8 Medium

CVSS2

Связанные уязвимости

nvd
около 12 лет назад

HTTP::Body::Multipart in the HTTP-Body module for Perl (1.07 through 1.22, before 1.23) uses the part of the uploaded file's name after the first "." character as the suffix of a temporary file, which makes it easier for remote attackers to conduct attacks by leveraging subsequent behavior that may assume the suffix is well-formed.

debian
около 12 лет назад

HTTP::Body::Multipart in the HTTP-Body module for Perl (1.07 through 1 ...

github
больше 3 лет назад

HTTP::Body::Multipart in the HTTP-Body 1.08, 1.17, and earlier module for Perl uses the part of the uploaded file's name after the first "." character as the suffix of a temporary file, which makes it easier for remote attackers to conduct attacks by leveraging subsequent behavior that may assume the suffix is well-formed.

6.8 Medium

CVSS2