[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

[3.4] perl-PathTools: Taint propagation flaw in canonpath() (CVE-2015-8607)

ID: oval:org.secpod.oval:def:1800866Date: (C)2018-03-29   (M)2022-09-22
Class: PATCHFamily: unix




It was reported that File::Spec::canonpath routine returns untainted strings even if passed tainted input. This defect undermines the guarantee of taint propagation, which is sometimes used to ensure that unvalidated user input does not reach sensitive code. This issue affects versions of PathTools from 3.47 onwards and/or perl 5.20.0.

Platform:
Alpine Linux 3.4
Product:
perl-pathtools
Reference:
5328
CVE-2015-8607
CVE    1
CVE-2015-8607
CPE    2
cpe:/o:alpinelinux:alpine_linux:3.4
cpe:/a:fedora_project:perl-pathtools

© SecPod Technologies