CVE-2011-1487
The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.6%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 10.58% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- perl/perl
- Source
- secalert@redhat.com
References
- http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057891.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057971.html
- http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html
- http://openwall.com/lists/oss-security/2011/04/01/3Exploit, Patch
- http://openwall.com/lists/oss-security/2011/04/04/35Exploit, Patch
- http://perl5.git.perl.org/perl.git/commit/539689e74a3bcb04d29e4cd9396de91a81045b99Patch
- http://rt.perl.org/rt3/Public/Bug/Display.html?id=87336Exploit
- http://secunia.com/advisories/43921Vendor Advisory
- http://secunia.com/advisories/44168
- http://www.debian.org/security/2011/dsa-2265
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:091
- http://www.securityfocus.com/bid/47124Exploit
- https://bugzilla.redhat.com/show_bug.cgi?id=692844
- https://bugzilla.redhat.com/show_bug.cgi?id=692898Exploit, Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66528
- http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057891.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057971.html
- http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html
- http://openwall.com/lists/oss-security/2011/04/01/3Exploit, Patch
- http://openwall.com/lists/oss-security/2011/04/04/35Exploit, Patch
- http://perl5.git.perl.org/perl.git/commit/539689e74a3bcb04d29e4cd9396de91a81045b99Patch
- http://rt.perl.org/rt3/Public/Bug/Display.html?id=87336Exploit
- http://secunia.com/advisories/43921Vendor Advisory
- http://secunia.com/advisories/44168
- http://www.debian.org/security/2011/dsa-2265
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:091
- http://www.securityfocus.com/bid/47124Exploit
- https://bugzilla.redhat.com/show_bug.cgi?id=692844
- https://bugzilla.redhat.com/show_bug.cgi?id=692898Exploit, Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66528
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.