CVE-2002-1323

Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of safe compartments in (1) Safe::reval or (2) Safe::rdo using a redefined @_ variable, which is not reset between successive calls.
References
Link Resource
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2004-007.0.txt
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.1/SCOSA-2004.1.txt
ftp://patches.sgi.com/support/free/security/advisories/20030606-01-A
http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0061.html
http://bugs6.perl.org/rt2/Ticket/Display.html?id=17744
http://marc.info/?l=bugtraq&m=104005919814869&w=2
http://marc.info/?l=bugtraq&m=104033126305252&w=2
http://marc.info/?l=bugtraq&m=104040175522502&w=2
http://use.perl.org/articles/02/10/06/1118222.shtml?tid=5 Patch
http://www.debian.org/security/2002/dsa-208 Patch Vendor Advisory
http://www.iss.net/security_center/static/10574.php Vendor Advisory
http://www.osvdb.org/2183
http://www.osvdb.org/3814
http://www.redhat.com/support/errata/RHSA-2003-256.html
http://www.redhat.com/support/errata/RHSA-2003-257.html
http://www.securityfocus.com/bid/6111 Patch Vendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1160
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2004-007.0.txt
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.1/SCOSA-2004.1.txt
ftp://patches.sgi.com/support/free/security/advisories/20030606-01-A
http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0061.html
http://bugs6.perl.org/rt2/Ticket/Display.html?id=17744
http://marc.info/?l=bugtraq&m=104005919814869&w=2
http://marc.info/?l=bugtraq&m=104033126305252&w=2
http://marc.info/?l=bugtraq&m=104040175522502&w=2
http://use.perl.org/articles/02/10/06/1118222.shtml?tid=5 Patch
http://www.debian.org/security/2002/dsa-208 Patch Vendor Advisory
http://www.iss.net/security_center/static/10574.php Vendor Advisory
http://www.osvdb.org/2183
http://www.osvdb.org/3814
http://www.redhat.com/support/errata/RHSA-2003-256.html
http://www.redhat.com/support/errata/RHSA-2003-257.html
http://www.securityfocus.com/bid/6111 Patch Vendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1160
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:safe.pm:safe.pm:2.0_6:*:*:*:*:*:*:*
cpe:2.3:a:safe.pm:safe.pm:2.0_7:*:*:*:*:*:*:*
cpe:2.3:a:sun:linux:5.0.7:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.1:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.2:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.3:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.4:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.5:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.6:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.7:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.8:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.9:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.10:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.11:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.12:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.13:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.14:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.15:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.16:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.17:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.17f:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.17m:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.18:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.18f:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.18m:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.19:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.19f:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.19m:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.20f:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.20m:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.21f:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.21m:*:*:*:*:*:*:*
cpe:2.3:o:sgi:irix:6.5.22:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:2.1:*:advanced_server:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:2.1:*:advanced_server_ia64:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:2.1:*:enterprise_server:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:2.1:*:enterprise_server_ia64:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:2.1:*:workstation:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:2.1:*:workstation_ia64:*:*:*:*:*
cpe:2.3:o:redhat:linux_advanced_workstation:2.1:*:*:*:*:*:*:*
cpe:2.3:o:sco:open_unix:8.0:*:*:*:*:*:*:*
cpe:2.3:o:sco:unixware:7.1.2:*:*:*:*:*:*:*
cpe:2.3:o:sco:unixware:7.1.3:*:*:*:*:*:*:*
cpe:2.3:o:sun:solaris:8.0:*:x86:*:*:*:*:*
cpe:2.3:o:sun:solaris:9.0:*:sparc:*:*:*:*:*
cpe:2.3:o:sun:solaris:9.0:*:x86:*:*:*:*:*
cpe:2.3:o:sun:sunos:5.8:*:*:*:*:*:*:*

History

20 Nov 2024, 23:41

Type Values Removed Values Added
References () ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2004-007.0.txt - () ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2004-007.0.txt -
References () ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.1/SCOSA-2004.1.txt - () ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.1/SCOSA-2004.1.txt -
References () ftp://patches.sgi.com/support/free/security/advisories/20030606-01-A - () ftp://patches.sgi.com/support/free/security/advisories/20030606-01-A -
References () http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0061.html - () http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0061.html -
References () http://bugs6.perl.org/rt2/Ticket/Display.html?id=17744 - () http://bugs6.perl.org/rt2/Ticket/Display.html?id=17744 -
References () http://marc.info/?l=bugtraq&m=104005919814869&w=2 - () http://marc.info/?l=bugtraq&m=104005919814869&w=2 -
References () http://marc.info/?l=bugtraq&m=104033126305252&w=2 - () http://marc.info/?l=bugtraq&m=104033126305252&w=2 -
References () http://marc.info/?l=bugtraq&m=104040175522502&w=2 - () http://marc.info/?l=bugtraq&m=104040175522502&w=2 -
References () http://use.perl.org/articles/02/10/06/1118222.shtml?tid=5 - Patch () http://use.perl.org/articles/02/10/06/1118222.shtml?tid=5 - Patch
References () http://www.debian.org/security/2002/dsa-208 - Patch, Vendor Advisory () http://www.debian.org/security/2002/dsa-208 - Patch, Vendor Advisory
References () http://www.iss.net/security_center/static/10574.php - Vendor Advisory () http://www.iss.net/security_center/static/10574.php - Vendor Advisory
References () http://www.osvdb.org/2183 - () http://www.osvdb.org/2183 -
References () http://www.osvdb.org/3814 - () http://www.osvdb.org/3814 -
References () http://www.redhat.com/support/errata/RHSA-2003-256.html - () http://www.redhat.com/support/errata/RHSA-2003-256.html -
References () http://www.redhat.com/support/errata/RHSA-2003-257.html - () http://www.redhat.com/support/errata/RHSA-2003-257.html -
References () http://www.securityfocus.com/bid/6111 - Patch, Vendor Advisory () http://www.securityfocus.com/bid/6111 - Patch, Vendor Advisory
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1160 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1160 -

Information

Published : 2002-12-11 05:00

Updated : 2024-11-20 23:41


NVD link : CVE-2002-1323

Mitre link : CVE-2002-1323

CVE.ORG link : CVE-2002-1323


JSON object : View

Products Affected

sun

  • linux
  • solaris
  • sunos

sgi

  • irix

sco

  • unixware
  • open_unix

safe.pm

  • safe.pm

redhat

  • enterprise_linux
  • linux_advanced_workstation