[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3441-1 perl -- perl

ID: oval:org.secpod.oval:def:602327Date: (C)2016-01-27   (M)2022-09-22
Class: PATCHFamily: unix




David Golden of MongoDB discovered that File::Spec::canonpath in Perl returned untainted strings even if passed tainted input. This defect undermines taint propagation, which is sometimes used to ensure that unvalidated user input does not reach sensitive code. The oldstable distribution is not affected by this problem.

Platform:
Debian 8.x
Product:
perl
Reference:
DSA-3441-1
CVE-2015-8607
CVE    1
CVE-2015-8607
CPE    2
cpe:/o:debian:debian_linux:8.x
cpe:/a:perl:perl

© SecPod Technologies