CVE-2010-1447
published 2010-05-19CVE-2010-1447: The Safe (aka Safe.pm) module 2.26, and certain earlier versions, for Perl, as used in PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2…
PriorityP345high8.5CVSS 2.0
AVNACMAuSCCICAC
EPSS
2.80%
84.9th percentile
The Safe (aka Safe.pm) module 2.26, and certain earlier versions, for Perl, as used in PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2, allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving subroutine references and delayed execution.
Affected
122 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | perl | < perl 5.12.3-1 (bookworm) | perl 5.12.3-1 (bookworm) |
| perl | perl | >= 0 < 5.12.3-1 | 5.12.3-1 |
| perl | perl | >= 0 < 5.12.3-1 | 5.12.3-1 |
| perl | perl | >= 0 < 5.12.3-1 | 5.12.3-1 |
| perl | perl | >= 0 < 5.12.3-1 | 5.12.3-1 |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
CVSS provenance
nvdv2.08.5HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
osv8.5HIGH
vendor_debian8.5HIGH
vendor_redhat8.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Perl vulnerabilities
vendor_ubuntu·2011-05-03·CVSS 7.5
CVE-2010-2761 [HIGH] Perl vulnerabilities
Title: Perl vulnerabilities
Summary: An attacker could send crafted input to Perl and bypass intended
restrictions.
It was discovered that the Safe.pm Perl module incorrectly handled
Safe::reval and Safe::rdo access restrictions. An attacker could use this
flaw to bypass intended restrictions and possibly execute arbitrary code.
(CVE-2010-1168, CVE-2010-1447)
It was discovered that the CGI.pm Perl module incorrectly handled certain
MIME boundary strings. An attacker could use this flaw to inject arbitrary
HTTP headers and perform HTTP response splitting and cross-site scripting
attacks. This issue only affected Ubuntu 6.06 LTS, 8.04 LTS, 10.04 LTS and
10.10. (CVE-2010-2761, CVE-2010-4411)
It was discovered that the CGI.pm Perl module incorrectly handled newline
characters. An attacker
Red Hat
PL/Tcl): SECURITY DEFINER function keyword bypass
vendor_redhat·2010-10-05·CVSS 7.5
CVE-2010-3433 [HIGH] PL/Tcl): SECURITY DEFINER function keyword bypass
PL/Tcl): SECURITY DEFINER function keyword bypass
The PL/perl and PL/Tcl implementations in PostgreSQL 7.4 before 7.4.30, 8.0 before 8.0.26, 8.1 before 8.1.22, 8.2 before 8.2.18, 8.3 before 8.3.12, 8.4 before 8.4.5, and 9.0 before 9.0.1 do not properly protect script execution by a different SQL user identity within the same session, which allows remote authenticated users to gain privileges via crafted script code in a SECURITY DEFINER function, as demonstrated by (1) redefining standard functions or (2) redefining operators, a different vulnerability than CVE-2010-1168, CVE-2010-1169, CVE-2010-1170, and CVE-2010-1447.
Red Hat
perl: Safe restriction bypass when reference to subroutine in compartment is called from outside
vendor_redhat·2010-05-17·CVSS 8.5
CVE-2010-1447 [HIGH] perl: Safe restriction bypass when reference to subroutine in compartment is called from outside
perl: Safe restriction bypass when reference to subroutine in compartment is called from outside
The Safe (aka Safe.pm) module 2.26, and certain earlier versions, for Perl, as used in PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2, allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving subroutine references and delayed execution.
Red Hat
PostgreSQL: PL/Perl Intended restriction bypass
vendor_redhat·2010-05-17·CVSS 8.5
CVE-2010-1169 [HIGH] PostgreSQL: PL/Perl Intended restriction bypass
PostgreSQL: PL/Perl Intended restriction bypass
PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2 does not properly restrict PL/perl procedures, which allows remote authenticated users, with database-creation privileges, to execute arbitrary Perl code via a crafted script, related to the Safe module (aka Safe.pm) for Perl. NOTE: some sources report that this issue is the same as CVE-2010-1447.
Package: postgresql (Red Hat Enterprise Linux 6) - Affected
Debian
CVE-2010-1447: perl - The Safe (aka Safe.pm) module 2.26, and certain earlier versions, for Perl, as u...
vendor_debian·2010·CVSS 8.5
CVE-2010-1447 [HIGH] CVE-2010-1447: perl - The Safe (aka Safe.pm) module 2.26, and certain earlier versions, for Perl, as u...
The Safe (aka Safe.pm) module 2.26, and certain earlier versions, for Perl, as used in PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2, allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving subroutine references and delayed execution.
Scope: local
bookworm: resolved (fixed in 5.12.3-1)
bullseye: resolved (fixed in 5.12.3-1)
forky: resolved (fixed in 5.12.3-1)
sid: resolved (fixed in 5.12.3-1)
trixie: resolved (fixed in 5.12.3-1)
GHSA
GHSA-gq7f-mcrw-ghw7: The PL/perl and PL/Tcl implementations in PostgreSQL 7
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2010-3433 [HIGH] GHSA-gq7f-mcrw-ghw7: The PL/perl and PL/Tcl implementations in PostgreSQL 7
The PL/perl and PL/Tcl implementations in PostgreSQL 7.4 before 7.4.30, 8.0 before 8.0.26, 8.1 before 8.1.22, 8.2 before 8.2.18, 8.3 before 8.3.12, 8.4 before 8.4.5, and 9.0 before 9.0.1 do not properly protect script execution by a different SQL user identity within the same session, which allows remote authenticated users to gain privileges via crafted script code in a SECURITY DEFINER function, as demonstrated by (1) redefining standard functions or (2) redefining operators, a different vulnerability than CVE-2010-1168, CVE-2010-1169, CVE-2010-1170, and CVE-2010-1447.
GHSA
GHSA-cjg9-jpjg-2p4r: PostgreSQL 7
ghsa_unreviewed·2022-05-02·CVSS 8.5
CVE-2010-1169 [HIGH] CWE-94 GHSA-cjg9-jpjg-2p4r: PostgreSQL 7
PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2 does not properly restrict PL/perl procedures, which allows remote authenticated users, with database-creation privileges, to execute arbitrary Perl code via a crafted script, related to the Safe module (aka Safe.pm) for Perl. NOTE: some sources report that this issue is the same as CVE-2010-1447.
GHSA
GHSA-f2r8-6hg3-mv9j: The Safe (aka Safe
ghsa_unreviewed·2022-05-02
CVE-2010-1447 [HIGH] GHSA-f2r8-6hg3-mv9j: The Safe (aka Safe
The Safe (aka Safe.pm) module 2.26, and certain earlier versions, for Perl, as used in PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2, allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving subroutine references and delayed execution.
OSV
CVE-2010-1447: The Safe (aka Safe
osv·2010-05-19·CVSS 8.5
CVE-2010-1447 [HIGH] CVE-2010-1447: The Safe (aka Safe
The Safe (aka Safe.pm) module 2.26, and certain earlier versions, for Perl, as used in PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2, allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving subroutine references and delayed execution.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-1974 perl: multiple unspecified vulnerabilities in Safe
bugzilla·2010-05-19·CVSS 7.5
CVE-2010-1974 [HIGH] CVE-2010-1974 perl: multiple unspecified vulnerabilities in Safe
CVE-2010-1974 perl: multiple unspecified vulnerabilities in Safe
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-1974 to
the following vulnerability:
Name: CVE-2010-1974
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1974
Assigned: 20100519
Reference: CONFIRM: http://blogs.perl.org/users/rafael_garcia-suarez/2010/03/new-safepm-fixes-security-hole.html
Reference: CONFIRM: http://cpansearch.perl.org/src/RGARCIA/Safe-2.27/Changes
Multiple unspecified vulnerabilities in the Safe (aka Safe.pm) module
before 2.25 for Perl allow context-dependent attackers to inject and
execute arbitrary code via vectors related to "automagic methods."
NOTE: this might overlap CVE-2010-1169 or CVE-2010-1447.
Discussion:
This is a duplicate of CVE-2010-1168, as explained in:
Bugzilla
CVE-2010-1447 perl: Safe restriction bypass when reference to subroutine in compartment is called from outside
bugzilla·2010-05-03·CVSS 7.5
CVE-2010-1447 [HIGH] CVE-2010-1447 perl: Safe restriction bypass when reference to subroutine in compartment is called from outside
CVE-2010-1447 perl: Safe restriction bypass when reference to subroutine in compartment is called from outside
Safe.pm 2.26 and earlier (except 2.20 through 2.23 if using a threads-enabled
Perl), when used in Perl 5.10.0 and earlier, may allow attackers to break out
of safe compartment in (1) Safe::reval or (2) Safe::rdo using subroutine
references, whose execution is delayed to happen outside of the safe
compartment.
If a victim was tricked into running a specially-crafted Perl script, using
Safe extension module, it could lead to intended Safe module restrictions
bypass, if the returned subroutine reference was called from outside of the
compartment.
Different vulnerability than CVE-2010-1168.
Solution: Ugrade to Safe.pm v2.27 or higher.
References:
[1] http://search.cpan.org/~rgarcia
Bugzilla
CVE-2010-1168 perl Safe: Intended restriction bypass via object references
bugzilla·2010-03-24·CVSS 7.5
CVE-2010-1168 [HIGH] CVE-2010-1168 perl Safe: Intended restriction bypass via object references
CVE-2010-1168 perl Safe: Intended restriction bypass via object references
Safe.pm 2.24 and earlier, when used in Perl 5.10.0 and earlier, may allow
attackers to break out of safe compartment in (1) Safe::reval or (2) Safe::rdo
using implicitly called methods (such as DESTROY or AUTOLOAD) on implicitly
blessed Perl objects, returned as a result of unsafe code evaluation. These
methods could have been executed unrestricted by Safe, when such objects were
accessed or destroyed.
If a victim was tricked into running a specially-crafted Perl script, using
Safe extension module, it could lead to intended Safe module restriction bypass.
Different vulnerability than CVE-2010-1447.
Solution: Upgrade to Safe.pm v2.25 or higher.
References:
[1] http://search.cpan.org/~rgarcia/Safe-2.27/Safe.pm
Ac
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://osvdb.org/64756http://secunia.com/advisories/39845http://secunia.com/advisories/40049http://secunia.com/advisories/40052http://security-tracker.debian.org/tracker/CVE-2010-1447http://www.debian.org/security/2011/dsa-2267http://www.mandriva.com/security/advisories?name=MDVSA-2010:115http://www.mandriva.com/security/advisories?name=MDVSA-2010:116http://www.openwall.com/lists/oss-security/2010/05/20/5http://www.postgresql.org/about/news.1203http://www.redhat.com/support/errata/RHSA-2010-0457.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0458.htmlhttp://www.securityfocus.com/bid/40305http://www.securitytracker.com/id?1023988http://www.vupen.com/english/advisories/2010/1167https://bugs.launchpad.net/bugs/cve/2010-1447https://bugzilla.redhat.com/show_bug.cgi?id=588269https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11530https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7320http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://osvdb.org/64756http://secunia.com/advisories/39845http://secunia.com/advisories/40049http://secunia.com/advisories/40052http://security-tracker.debian.org/tracker/CVE-2010-1447http://www.debian.org/security/2011/dsa-2267http://www.mandriva.com/security/advisories?name=MDVSA-2010:115http://www.mandriva.com/security/advisories?name=MDVSA-2010:116http://www.openwall.com/lists/oss-security/2010/05/20/5http://www.postgresql.org/about/news.1203http://www.redhat.com/support/errata/RHSA-2010-0457.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0458.htmlhttp://www.securityfocus.com/bid/40305http://www.securitytracker.com/id?1023988http://www.vupen.com/english/advisories/2010/1167https://bugs.launchpad.net/bugs/cve/2010-1447https://bugzilla.redhat.com/show_bug.cgi?id=588269https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11530https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7320
2010-05-19
Published