Количество 15
Количество 15
CVE-2026-48962
IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege.
CVE-2026-48962
IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege.
CVE-2026-48962
IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege.
CVE-2026-48962
IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob
CVE-2026-48962
IO::Compress versions before 2.220 for Perl can execute arbitrary code ...
RLSA-2026:30860
Important: perl-IO-Compress security update
RLSA-2026:30859
Important: perl-IO-Compress security update
GHSA-q6wx-vhvq-x7h6
IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege.
ELSA-2026-30860
ELSA-2026-30860: perl-IO-Compress security update (IMPORTANT)
ELSA-2026-30859
ELSA-2026-30859: perl-IO-Compress security update (IMPORTANT)
ELSA-2026-30858
ELSA-2026-30858: perl-IO-Compress security update (IMPORTANT)
ELSA-2026-30843
ELSA-2026-30843: perl-IO-Compress security update (IMPORTANT)
openSUSE-SU-2026:21177-1
Security update for perl-IO-Compress
RLSA-2026:30851
Important: perl:5.32 security update
ELSA-2026-30851
ELSA-2026-30851: perl:5.32 security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-48962 IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege. | CVSS3: 7.3 | 0% Низкий | 2 месяца назад | |
CVE-2026-48962 IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-48962 IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege. | CVSS3: 7.3 | 0% Низкий | 2 месяца назад | |
CVE-2026-48962 IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob | CVSS3: 7.3 | 0% Низкий | 2 месяца назад | |
CVE-2026-48962 IO::Compress versions before 2.220 for Perl can execute arbitrary code ... | CVSS3: 7.3 | 0% Низкий | 2 месяца назад | |
RLSA-2026:30860 Important: perl-IO-Compress security update | 0% Низкий | 27 дней назад | ||
RLSA-2026:30859 Important: perl-IO-Compress security update | 0% Низкий | около 1 месяца назад | ||
GHSA-q6wx-vhvq-x7h6 IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege. | CVSS3: 7.3 | 0% Низкий | 2 месяца назад | |
ELSA-2026-30860 ELSA-2026-30860: perl-IO-Compress security update (IMPORTANT) | 16 дней назад | |||
ELSA-2026-30859 ELSA-2026-30859: perl-IO-Compress security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-30858 ELSA-2026-30858: perl-IO-Compress security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-30843 ELSA-2026-30843: perl-IO-Compress security update (IMPORTANT) | 11 дней назад | |||
openSUSE-SU-2026:21177-1 Security update for perl-IO-Compress | около 1 месяца назад | |||
RLSA-2026:30851 Important: perl:5.32 security update | около 1 месяца назад | |||
ELSA-2026-30851 ELSA-2026-30851: perl:5.32 security update (IMPORTANT) | около 1 месяца назад |
Уязвимостей на страницу