CVE-2010-1168
published 2010-06-21CVE-2010-1168: The Safe (aka Safe.pm) module before 2.25 for Perl allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions…
PriorityP343high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.72%
88.6th percentile
The Safe (aka Safe.pm) module before 2.25 for Perl allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving implicitly called methods and implicitly blessed objects, as demonstrated by the (a) DESTROY and (b) AUTOLOAD methods, related to "automagic methods."
Affected
134 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | perl | < perl 5.10.1-13 (bookworm) | perl 5.10.1-13 (bookworm) |
| perl | perl | >= 0 < 5.10.1-13 | 5.10.1-13 |
| perl | perl | >= 0 < 5.10.1-13 | 5.10.1-13 |
| perl | perl | >= 0 < 5.10.1-13 | 5.10.1-13 |
| perl | perl | >= 0 < 5.10.1-13 | 5.10.1-13 |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Perl vulnerabilities
vendor_ubuntu·2011-05-03·CVSS 7.5
CVE-2010-2761 [HIGH] Perl vulnerabilities
Title: Perl vulnerabilities
Summary: An attacker could send crafted input to Perl and bypass intended
restrictions.
It was discovered that the Safe.pm Perl module incorrectly handled
Safe::reval and Safe::rdo access restrictions. An attacker could use this
flaw to bypass intended restrictions and possibly execute arbitrary code.
(CVE-2010-1168, CVE-2010-1447)
It was discovered that the CGI.pm Perl module incorrectly handled certain
MIME boundary strings. An attacker could use this flaw to inject arbitrary
HTTP headers and perform HTTP response splitting and cross-site scripting
attacks. This issue only affected Ubuntu 6.06 LTS, 8.04 LTS, 10.04 LTS and
10.10. (CVE-2010-2761, CVE-2010-4411)
It was discovered that the CGI.pm Perl module incorrectly handled newline
characters. An attacker
Red Hat
PL/Tcl): SECURITY DEFINER function keyword bypass
vendor_redhat·2010-10-05·CVSS 7.5
CVE-2010-3433 [HIGH] PL/Tcl): SECURITY DEFINER function keyword bypass
PL/Tcl): SECURITY DEFINER function keyword bypass
The PL/perl and PL/Tcl implementations in PostgreSQL 7.4 before 7.4.30, 8.0 before 8.0.26, 8.1 before 8.1.22, 8.2 before 8.2.18, 8.3 before 8.3.12, 8.4 before 8.4.5, and 9.0 before 9.0.1 do not properly protect script execution by a different SQL user identity within the same session, which allows remote authenticated users to gain privileges via crafted script code in a SECURITY DEFINER function, as demonstrated by (1) redefining standard functions or (2) redefining operators, a different vulnerability than CVE-2010-1168, CVE-2010-1169, CVE-2010-1170, and CVE-2010-1447.
Red Hat
Safe: Intended restriction bypass via object references
vendor_redhat·2010-05-20·CVSS 7.5
CVE-2010-1168 [HIGH] Safe: Intended restriction bypass via object references
Safe: Intended restriction bypass via object references
The Safe (aka Safe.pm) module before 2.25 for Perl allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving implicitly called methods and implicitly blessed objects, as demonstrated by the (a) DESTROY and (b) AUTOLOAD methods, related to "automagic methods."
Red Hat
perl: multiple unspecified vulnerabilities in Safe
vendor_redhat·2010-05-08·CVSS 7.5
CVE-2010-1974 [HIGH] perl: multiple unspecified vulnerabilities in Safe
perl: multiple unspecified vulnerabilities in Safe
No description is available for this CVE.
Statement: This flaw was found to be a duplicate of CVE-2010-1168. Please see https://access.redhat.com/security/cve/CVE-2010-1168 for information about affected products and security errata.
Package: perl (Red Hat Enterprise Linux 4) - Not affected
Package: perl (Red Hat Enterprise Linux 5) - Not affected
Package: perl (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2010-1168: perl - The Safe (aka Safe.pm) module before 2.25 for Perl allows context-dependent atta...
vendor_debian·2010·CVSS 7.5
CVE-2010-1168 [HIGH] CVE-2010-1168: perl - The Safe (aka Safe.pm) module before 2.25 for Perl allows context-dependent atta...
The Safe (aka Safe.pm) module before 2.25 for Perl allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving implicitly called methods and implicitly blessed objects, as demonstrated by the (a) DESTROY and (b) AUTOLOAD methods, related to "automagic methods."
Scope: local
bookworm: resolved (fixed in 5.10.1-13)
bullseye: resolved (fixed in 5.10.1-13)
forky: resolved (fixed in 5.10.1-13)
sid: resolved (fixed in 5.10.1-13)
trixie: resolved (fixed in 5.10.1-13)
GHSA
GHSA-gq7f-mcrw-ghw7: The PL/perl and PL/Tcl implementations in PostgreSQL 7
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2010-3433 [HIGH] GHSA-gq7f-mcrw-ghw7: The PL/perl and PL/Tcl implementations in PostgreSQL 7
The PL/perl and PL/Tcl implementations in PostgreSQL 7.4 before 7.4.30, 8.0 before 8.0.26, 8.1 before 8.1.22, 8.2 before 8.2.18, 8.3 before 8.3.12, 8.4 before 8.4.5, and 9.0 before 9.0.1 do not properly protect script execution by a different SQL user identity within the same session, which allows remote authenticated users to gain privileges via crafted script code in a SECURITY DEFINER function, as demonstrated by (1) redefining standard functions or (2) redefining operators, a different vulnerability than CVE-2010-1168, CVE-2010-1169, CVE-2010-1170, and CVE-2010-1447.
GHSA
GHSA-wvgg-c5pp-f6w9: The Safe (aka Safe
ghsa_unreviewed·2022-05-02
CVE-2010-1168 [HIGH] GHSA-wvgg-c5pp-f6w9: The Safe (aka Safe
The Safe (aka Safe.pm) module before 2.25 for Perl allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving implicitly called methods and implicitly blessed objects, as demonstrated by the (a) DESTROY and (b) AUTOLOAD methods, related to "automagic methods."
OSV
CVE-2010-1168: The Safe (aka Safe
osv·2010-06-21·CVSS 7.5
CVE-2010-1168 [HIGH] CVE-2010-1168: The Safe (aka Safe
The Safe (aka Safe.pm) module before 2.25 for Perl allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving implicitly called methods and implicitly blessed objects, as demonstrated by the (a) DESTROY and (b) AUTOLOAD methods, related to "automagic methods."
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-1974 perl: multiple unspecified vulnerabilities in Safe
bugzilla·2010-05-19·CVSS 7.5
CVE-2010-1974 [HIGH] CVE-2010-1974 perl: multiple unspecified vulnerabilities in Safe
CVE-2010-1974 perl: multiple unspecified vulnerabilities in Safe
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-1974 to
the following vulnerability:
Name: CVE-2010-1974
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1974
Assigned: 20100519
Reference: CONFIRM: http://blogs.perl.org/users/rafael_garcia-suarez/2010/03/new-safepm-fixes-security-hole.html
Reference: CONFIRM: http://cpansearch.perl.org/src/RGARCIA/Safe-2.27/Changes
Multiple unspecified vulnerabilities in the Safe (aka Safe.pm) module
before 2.25 for Perl allow context-dependent attackers to inject and
execute arbitrary code via vectors related to "automagic methods."
NOTE: this might overlap CVE-2010-1169 or CVE-2010-1447.
Discussion:
This is a duplicate of CVE-2010-1168, as explained in:
Bugzilla
CVE-2010-1447 perl: Safe restriction bypass when reference to subroutine in compartment is called from outside
bugzilla·2010-05-03·CVSS 7.5
CVE-2010-1447 [HIGH] CVE-2010-1447 perl: Safe restriction bypass when reference to subroutine in compartment is called from outside
CVE-2010-1447 perl: Safe restriction bypass when reference to subroutine in compartment is called from outside
Safe.pm 2.26 and earlier (except 2.20 through 2.23 if using a threads-enabled
Perl), when used in Perl 5.10.0 and earlier, may allow attackers to break out
of safe compartment in (1) Safe::reval or (2) Safe::rdo using subroutine
references, whose execution is delayed to happen outside of the safe
compartment.
If a victim was tricked into running a specially-crafted Perl script, using
Safe extension module, it could lead to intended Safe module restrictions
bypass, if the returned subroutine reference was called from outside of the
compartment.
Different vulnerability than CVE-2010-1168.
Solution: Ugrade to Safe.pm v2.27 or higher.
References:
[1] http://search.cpan.org/~rgarcia
Bugzilla
CVE-2010-1168 perl Safe: Intended restriction bypass via object references
bugzilla·2010-03-24·CVSS 7.5
CVE-2010-1168 [HIGH] CVE-2010-1168 perl Safe: Intended restriction bypass via object references
CVE-2010-1168 perl Safe: Intended restriction bypass via object references
Safe.pm 2.24 and earlier, when used in Perl 5.10.0 and earlier, may allow
attackers to break out of safe compartment in (1) Safe::reval or (2) Safe::rdo
using implicitly called methods (such as DESTROY or AUTOLOAD) on implicitly
blessed Perl objects, returned as a result of unsafe code evaluation. These
methods could have been executed unrestricted by Safe, when such objects were
accessed or destroyed.
If a victim was tricked into running a specially-crafted Perl script, using
Safe extension module, it could lead to intended Safe module restriction bypass.
Different vulnerability than CVE-2010-1447.
Solution: Upgrade to Safe.pm v2.25 or higher.
References:
[1] http://search.cpan.org/~rgarcia/Safe-2.27/Safe.pm
Ac
http://blogs.perl.org/users/rafael_garcia-suarez/2010/03/new-safepm-fixes-security-hole.htmlhttp://blogs.sun.com/security/entry/cve_2010_1168_vulnerability_inhttp://cpansearch.perl.org/src/RGARCIA/Safe-2.27/Changeshttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735http://secunia.com/advisories/40049http://secunia.com/advisories/40052http://secunia.com/advisories/42402http://securitytracker.com/id?1024062http://www.mandriva.com/security/advisories?name=MDVSA-2010:115http://www.mandriva.com/security/advisories?name=MDVSA-2010:116http://www.openwall.com/lists/oss-security/2010/05/20/5http://www.redhat.com/support/errata/RHSA-2010-0457.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0458.htmlhttp://www.vupen.com/english/advisories/2010/3075https://bugzilla.redhat.com/show_bug.cgi?id=576508https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7424https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9807http://blogs.perl.org/users/rafael_garcia-suarez/2010/03/new-safepm-fixes-security-hole.htmlhttp://blogs.sun.com/security/entry/cve_2010_1168_vulnerability_inhttp://cpansearch.perl.org/src/RGARCIA/Safe-2.27/Changeshttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735http://secunia.com/advisories/40049http://secunia.com/advisories/40052http://secunia.com/advisories/42402http://securitytracker.com/id?1024062http://www.mandriva.com/security/advisories?name=MDVSA-2010:115http://www.mandriva.com/security/advisories?name=MDVSA-2010:116http://www.openwall.com/lists/oss-security/2010/05/20/5http://www.redhat.com/support/errata/RHSA-2010-0457.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0458.htmlhttp://www.vupen.com/english/advisories/2010/3075https://bugzilla.redhat.com/show_bug.cgi?id=576508https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7424https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9807
2010-06-21
Published