Количество 26
Количество 26
RLSA-2026:30851
Important: perl:5.32 security update
ELSA-2026-30851
ELSA-2026-30851: perl:5.32 security update (IMPORTANT)
CVE-2026-42496
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.
CVE-2026-42496
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.
CVE-2026-42496
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.
CVE-2026-42496
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory
CVE-2026-42496
Archive::Tar versions before 3.08 for Perl extract symlinks with attac ...
CVE-2026-48962
IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege.
CVE-2026-48962
IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege.
CVE-2026-48962
IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege.
CVE-2026-48962
IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob
CVE-2026-48962
IO::Compress versions before 2.220 for Perl can execute arbitrary code ...
RLSA-2026:30857
Important: perl-Archive-Tar security update
RLSA-2026:30856
Important: perl-Archive-Tar security update
GHSA-8p37-q9qq-hgx8
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.
ELSA-2026-30857
ELSA-2026-30857: perl-Archive-Tar security update (IMPORTANT)
ELSA-2026-30856
ELSA-2026-30856: perl-Archive-Tar security update (IMPORTANT)
ELSA-2026-30852
ELSA-2026-30852: perl-Archive-Tar security update (IMPORTANT)
RLSA-2026:30860
Important: perl-IO-Compress security update
RLSA-2026:30859
Important: perl-IO-Compress security update
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
RLSA-2026:30851 Important: perl:5.32 security update | около 1 месяца назад | |||
ELSA-2026-30851 ELSA-2026-30851: perl:5.32 security update (IMPORTANT) | около 1 месяца назад | |||
CVE-2026-42496 Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path. | CVSS3: 9.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-42496 Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path. | CVSS3: 8.2 | 0% Низкий | 2 месяца назад | |
CVE-2026-42496 Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path. | CVSS3: 9.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-42496 Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory | CVSS3: 9.1 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-42496 Archive::Tar versions before 3.08 for Perl extract symlinks with attac ... | CVSS3: 9.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-48962 IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege. | CVSS3: 7.3 | 0% Низкий | 2 месяца назад | |
CVE-2026-48962 IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-48962 IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege. | CVSS3: 7.3 | 0% Низкий | 2 месяца назад | |
CVE-2026-48962 IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob | CVSS3: 7.3 | 0% Низкий | 2 месяца назад | |
CVE-2026-48962 IO::Compress versions before 2.220 for Perl can execute arbitrary code ... | CVSS3: 7.3 | 0% Низкий | 2 месяца назад | |
RLSA-2026:30857 Important: perl-Archive-Tar security update | 0% Низкий | 27 дней назад | ||
RLSA-2026:30856 Important: perl-Archive-Tar security update | 0% Низкий | около 1 месяца назад | ||
GHSA-8p37-q9qq-hgx8 Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path. | CVSS3: 9.1 | 0% Низкий | 2 месяца назад | |
ELSA-2026-30857 ELSA-2026-30857: perl-Archive-Tar security update (IMPORTANT) | 16 дней назад | |||
ELSA-2026-30856 ELSA-2026-30856: perl-Archive-Tar security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-30852 ELSA-2026-30852: perl-Archive-Tar security update (IMPORTANT) | около 1 месяца назад | |||
RLSA-2026:30860 Important: perl-IO-Compress security update | 0% Низкий | 27 дней назад | ||
RLSA-2026:30859 Important: perl-IO-Compress security update | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу