[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2011:091 -- Mandriva perl

ID: oval:org.secpod.oval:def:301020Date: (C)2012-01-07   (M)2021-09-11
Class: PATCHFamily: unix




A vulnerability has been found and corrected in perl: The lc, lcfirst, uc, and ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string . Packages for 2009.0 are provided as of the Extended Maintenance Program

Platform:
Mandriva Linux 2010.1
Mandriva Linux 2009.0
Product:
perl
Reference:
MDVSA-2011:091
CVE-2011-1487
CVE    1
CVE-2011-1487
CPE    2
cpe:/o:mandriva:linux:2009.0
cpe:/o:mandriva:linux:2010.1

© SecPod Technologies