CVE-2010-1168

The Safe (aka Safe.pm) module before 2.25 for Perl allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving implicitly called methods and implicitly blessed objects, as demonstrated by the (a) DESTROY and (b) AUTOLOAD methods, related to "automagic methods."
References
Link Resource
http://blogs.perl.org/users/rafael_garcia-suarez/2010/03/new-safepm-fixes-security-hole.html
http://blogs.sun.com/security/entry/cve_2010_1168_vulnerability_in
http://cpansearch.perl.org/src/RGARCIA/Safe-2.27/Changes
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735
http://secunia.com/advisories/40049 Vendor Advisory
http://secunia.com/advisories/40052 Vendor Advisory
http://secunia.com/advisories/42402
http://securitytracker.com/id?1024062 Vendor Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2010:115
http://www.mandriva.com/security/advisories?name=MDVSA-2010:116
http://www.openwall.com/lists/oss-security/2010/05/20/5
http://www.redhat.com/support/errata/RHSA-2010-0457.html Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2010-0458.html Vendor Advisory
http://www.vupen.com/english/advisories/2010/3075
https://bugzilla.redhat.com/show_bug.cgi?id=576508
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7424
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9807
http://blogs.perl.org/users/rafael_garcia-suarez/2010/03/new-safepm-fixes-security-hole.html
http://blogs.sun.com/security/entry/cve_2010_1168_vulnerability_in
http://cpansearch.perl.org/src/RGARCIA/Safe-2.27/Changes
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735
http://secunia.com/advisories/40049 Vendor Advisory
http://secunia.com/advisories/40052 Vendor Advisory
http://secunia.com/advisories/42402
http://securitytracker.com/id?1024062 Vendor Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2010:115
http://www.mandriva.com/security/advisories?name=MDVSA-2010:116
http://www.openwall.com/lists/oss-security/2010/05/20/5
http://www.redhat.com/support/errata/RHSA-2010-0457.html Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2010-0458.html Vendor Advisory
http://www.vupen.com/english/advisories/2010/3075
https://bugzilla.redhat.com/show_bug.cgi?id=576508
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7424
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9807
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:rafael_garcia-suarez:safe:2.08:*:*:*:*:*:*:*
cpe:2.3:a:rafael_garcia-suarez:safe:2.09:*:*:*:*:*:*:*
cpe:2.3:a:rafael_garcia-suarez:safe:2.11:*:*:*:*:*:*:*
cpe:2.3:a:rafael_garcia-suarez:safe:2.13:*:*:*:*:*:*:*
cpe:2.3:a:rafael_garcia-suarez:safe:2.14:*:*:*:*:*:*:*
cpe:2.3:a:rafael_garcia-suarez:safe:2.15:*:*:*:*:*:*:*
cpe:2.3:a:rafael_garcia-suarez:safe:2.16:*:*:*:*:*:*:*
cpe:2.3:a:rafael_garcia-suarez:safe:2.17:*:*:*:*:*:*:*
cpe:2.3:a:rafael_garcia-suarez:safe:2.18:*:*:*:*:*:*:*
cpe:2.3:a:rafael_garcia-suarez:safe:2.19:*:*:*:*:*:*:*
cpe:2.3:a:rafael_garcia-suarez:safe:2.20:*:*:*:*:*:*:*
cpe:2.3:a:rafael_garcia-suarez:safe:2.21:*:*:*:*:*:*:*
cpe:2.3:a:rafael_garcia-suarez:safe:2.22:*:*:*:*:*:*:*
cpe:2.3:a:rafael_garcia-suarez:safe:2.23:*:*:*:*:*:*:*
cpe:2.3:a:rafael_garcia-suarez:safe:2.24:*:*:*:*:*:*:*
cpe:2.3:a:perl:perl:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:13

Type Values Removed Values Added
References () http://blogs.perl.org/users/rafael_garcia-suarez/2010/03/new-safepm-fixes-security-hole.html - () http://blogs.perl.org/users/rafael_garcia-suarez/2010/03/new-safepm-fixes-security-hole.html -
References () http://blogs.sun.com/security/entry/cve_2010_1168_vulnerability_in - () http://blogs.sun.com/security/entry/cve_2010_1168_vulnerability_in -
References () http://cpansearch.perl.org/src/RGARCIA/Safe-2.27/Changes - () http://cpansearch.perl.org/src/RGARCIA/Safe-2.27/Changes -
References () http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705 - () http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705 -
References () http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735 - () http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735 -
References () http://secunia.com/advisories/40049 - Vendor Advisory () http://secunia.com/advisories/40049 - Vendor Advisory
References () http://secunia.com/advisories/40052 - Vendor Advisory () http://secunia.com/advisories/40052 - Vendor Advisory
References () http://secunia.com/advisories/42402 - () http://secunia.com/advisories/42402 -
References () http://securitytracker.com/id?1024062 - Vendor Advisory () http://securitytracker.com/id?1024062 - Vendor Advisory
References () http://www.mandriva.com/security/advisories?name=MDVSA-2010:115 - () http://www.mandriva.com/security/advisories?name=MDVSA-2010:115 -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2010:116 - () http://www.mandriva.com/security/advisories?name=MDVSA-2010:116 -
References () http://www.openwall.com/lists/oss-security/2010/05/20/5 - () http://www.openwall.com/lists/oss-security/2010/05/20/5 -
References () http://www.redhat.com/support/errata/RHSA-2010-0457.html - Vendor Advisory () http://www.redhat.com/support/errata/RHSA-2010-0457.html - Vendor Advisory
References () http://www.redhat.com/support/errata/RHSA-2010-0458.html - Vendor Advisory () http://www.redhat.com/support/errata/RHSA-2010-0458.html - Vendor Advisory
References () http://www.vupen.com/english/advisories/2010/3075 - () http://www.vupen.com/english/advisories/2010/3075 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=576508 - () https://bugzilla.redhat.com/show_bug.cgi?id=576508 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7424 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7424 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9807 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9807 -

Information

Published : 2010-06-21 16:30

Updated : 2024-11-21 01:13


NVD link : CVE-2010-1168

Mitre link : CVE-2010-1168

CVE.ORG link : CVE-2010-1168


JSON object : View

Products Affected

perl

  • perl

rafael_garcia-suarez

  • safe
CWE
CWE-264

Permissions, Privileges, and Access Controls