Описание
The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was not-affected [3.4000-1ubuntu2]] |
| precise | not-affected | 3.3300-1build2 |
| trusty | not-affected | 3.4000-1ubuntu2 |
| trusty/esm | DNE | trusty was not-affected [3.4000-1ubuntu2] |
| upstream | needs-triage | |
| vivid | DNE | |
| vivid/stable-phone-overlay | DNE | |
| vivid/ubuntu-core | DNE | |
| wily | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 5.22.1-4 |
| esm-infra-legacy/trusty | not-affected | 5.18.2-2ubuntu1 |
| precise | not-affected | 5.14.2-6ubuntu2.4 |
| trusty | not-affected | 5.18.2-2ubuntu1 |
| trusty/esm | not-affected | 5.18.2-2ubuntu1 |
| upstream | needs-triage | |
| vivid | released | 5.20.2-2ubuntu0.1 |
| vivid/stable-phone-overlay | released | 5.20.2-2ubuntu0.1 |
| vivid/ubuntu-core | released | 5.20.2-2ubuntu0.1 |
| wily | released | 5.20.2-6ubuntu0.1 |
Показывать по
EPSS
7.5 High
CVSS2
7.3 High
CVSS3
Связанные уязвимости
The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.
The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.
The canonpath function in the File::Spec module in PathTools before 3. ...
The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.
EPSS
7.5 High
CVSS2
7.3 High
CVSS3