[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2012-6329Date: (C)2013-01-07   (M)2023-12-22


The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly handle backslashes and fully qualified method names during compilation of bracket notation, which allows context-dependent attackers to execute arbitrary commands via crafted input to an application that accepts translation strings from users, as demonstrated by the TWiki application before 5.1.3, and the Foswiki application 1.0.x through 1.0.10 and 1.1.x through 1.1.6.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
BID-56950
MDVSA-2013:113
RHSA-2013:0685
USN-2099-1
http://sourceforge.net/mailarchive/message.php?msg_id=30219695
http://openwall.com/lists/oss-security/2012/12/11/4
http://code.activestate.com/lists/perl5-porters/187763/
http://code.activestate.com/lists/perl5-porters/187746/
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=695224
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735
http://perl5.git.perl.org/perl.git/blob/HEAD:/pod/perl5177delta.pod
http://perl5.git.perl.org/perl.git/commit/1735f6f53ca19f99c6e9e39496c486af323ba6a8
http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2012-6329
http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
https://bugzilla.redhat.com/show_bug.cgi?id=884354
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0032

CPE    51
cpe:/a:perl:perl:5.12.1
cpe:/a:perl:perl:5.12.0
cpe:/a:perl:perl:5.10.1
cpe:/a:perl:perl:5.16.0
...
CWE    1
CWE-94
OVAL    15
oval:org.secpod.oval:def:104646
oval:org.secpod.oval:def:104761
oval:org.secpod.oval:def:701561
oval:org.secpod.oval:def:21280
...

© SecPod Technologies