[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2801-1 libhttp-body-perl -- design error

ID: oval:org.secpod.oval:def:601153Date: (C)2014-01-08   (M)2024-04-17
Class: PATCHFamily: unix




Jonathan Dolle reported a design error in HTTP::Body, a Perl module for processing data from HTTP POST requests. The HTTP body multipart parser creates temporary files which preserve the suffix of the uploaded file. An attacker able to upload files to a service that uses HTTP::Body::Multipart could potentially execute commands on the server if these temporary filenames are used in subsequent commands without further checks. This update restricts the possible suffixes used for the created temporary files. The oldstable distribution is not affected by this problem.

Platform:
Debian 7.0
Product:
libhttp-body-perl
Reference:
DSA-2801-1
CVE-2013-4407
CVE    1
CVE-2013-4407
CPE    2
cpe:/a:http-body_project:libhttp-body-perl
cpe:/o:debian:debian_linux:7.0

© SecPod Technologies