CVE-2002-1323

7 documents7 sources
Severity
4.6MEDIUM
EPSS
0.1%
top 75.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 11
Latest updateMay 3

Description

Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of safe compartments in (1) Safe::reval or (2) Safe::rdo using a redefined @_ variable, which is not reset between successive calls.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages9 packages

NVDsafe.pm/safe.pm2.0_6, 2.0_7+1
Debianperl< 5.8.0-14+3
NVDsgi/irix31 versions+30
NVDsun/linux5.0.7
NVDsun/sunos5.8

Also affects: Enterprise Linux 2.1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-qmvp-2m2m-rm8h: Safe2022-05-03
CVEList
CVE-2002-1323: Safe2004-09-01
OSV
CVE-2002-1323: Safe2002-12-11

📋Vendor Advisories

2
Red Hat
security flaw2002-10-04
Debian
CVE-2002-1323: perl - Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attack...2002

💬Community

1
Bugzilla
CVE-2002-1323 security flaw2018-08-16