[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2265-1 perl -- lack of tainted flag propagation

ID: oval:org.secpod.oval:def:600572Date: (C)2011-06-23   (M)2022-10-10
Class: PATCHFamily: unix




Mark Martinec discovered that Perl incorrectly clears the tainted flag on values returned by case conversion functions such as "lc". This may expose preexisting vulnerabilities in applications which use these functions while processing untrusted input. No such applications are known at this stage. Such applications will cease to work when this security update is applied because taint checks are designed to prevent such unsafe use of untrusted input data.

Platform:
Debian 5.0
Debian 6.0
Product:
perl
Reference:
DSA-2265-1
CVE-2011-1487
CVE    1
CVE-2011-1487
CPE    43
cpe:/a:perl:perl:5.11.2
cpe:/a:perl:perl:5.12.1
cpe:/a:perl:perl:5.12.3:rc3
cpe:/a:perl:perl:5.13.0
...

© SecPod Technologies