Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-8607

Опубликовано: 13 янв. 2016
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 7.3

Описание

The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [3.4000-1ubuntu2]]
precise

not-affected

3.3300-1build2
trusty

not-affected

3.4000-1ubuntu2
trusty/esm

DNE

trusty was not-affected [3.4000-1ubuntu2]
upstream

needs-triage

vivid

DNE

vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

wily

DNE

Показывать по

РелизСтатусПримечание
devel

not-affected

5.22.1-4
esm-infra-legacy/trusty

not-affected

5.18.2-2ubuntu1
precise

not-affected

5.14.2-6ubuntu2.4
trusty

not-affected

5.18.2-2ubuntu1
trusty/esm

not-affected

5.18.2-2ubuntu1
upstream

needs-triage

vivid

released

5.20.2-2ubuntu0.1
vivid/stable-phone-overlay

released

5.20.2-2ubuntu0.1
vivid/ubuntu-core

released

5.20.2-2ubuntu0.1
wily

released

5.20.2-6ubuntu0.1

Показывать по

EPSS

Процентиль: 90%
0.05664
Низкий

7.5 High

CVSS2

7.3 High

CVSS3

Связанные уязвимости

redhat
около 10 лет назад

The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

CVSS3: 7.3
nvd
около 10 лет назад

The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

CVSS3: 7.3
debian
около 10 лет назад

The canonpath function in the File::Spec module in PathTools before 3. ...

CVSS3: 7.3
github
больше 3 лет назад

The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

EPSS

Процентиль: 90%
0.05664
Низкий

7.5 High

CVSS2

7.3 High

CVSS3