VulnerabilityModified
CVE-2002-1323
Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of safe compartments in (1) Safe::reval or (2) Safe::rdo using a redefined @_ variable, which is not reset between successive calls.
MEDIUM 4.6EPSS 0.46%
Does this matter?
Lower severity and a low EPSS score (0.46%). Track it; it rarely justifies an emergency change on its own.
Description
Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of safe compartments in (1) Safe::reval or (2) Safe::rdo using a redefined @_ variable, which is not reset between successive calls.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.46% probability · 39th percentile
- CISA KEV
- Not listed
- Affected
- safe.pm/safe.pm · sun/linux · sgi/irix · redhat/enterprise linux · redhat/linux advanced workstation · sco/open unix · sco/unixware · sun/solaris · sun/sunos
- Source
- cve@mitre.org
References
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2004-007.0.txt
- ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.1/SCOSA-2004.1.txt
- ftp://patches.sgi.com/support/free/security/advisories/20030606-01-A
- http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0061.html
- http://bugs6.perl.org/rt2/Ticket/Display.html?id=17744
- http://marc.info/?l=bugtraq&m=104005919814869&w=2
- http://marc.info/?l=bugtraq&m=104033126305252&w=2
- http://marc.info/?l=bugtraq&m=104040175522502&w=2
- http://use.perl.org/articles/02/10/06/1118222.shtml?tid=5Patch
- http://www.debian.org/security/2002/dsa-208Patch, Vendor Advisory
- http://www.iss.net/security_center/static/10574.phpVendor Advisory
- http://www.osvdb.org/2183
- http://www.osvdb.org/3814
- http://www.redhat.com/support/errata/RHSA-2003-256.html
- http://www.redhat.com/support/errata/RHSA-2003-257.html
- http://www.securityfocus.com/bid/6111Patch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1160
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2004-007.0.txt
- ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.1/SCOSA-2004.1.txt
- ftp://patches.sgi.com/support/free/security/advisories/20030606-01-A
- http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0061.html
- http://bugs6.perl.org/rt2/Ticket/Display.html?id=17744
- http://marc.info/?l=bugtraq&m=104005919814869&w=2
- http://marc.info/?l=bugtraq&m=104033126305252&w=2
- http://marc.info/?l=bugtraq&m=104040175522502&w=2
- http://use.perl.org/articles/02/10/06/1118222.shtml?tid=5Patch
- http://www.debian.org/security/2002/dsa-208Patch, Vendor Advisory
- http://www.iss.net/security_center/static/10574.phpVendor Advisory
- http://www.osvdb.org/2183
- http://www.osvdb.org/3814
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.