CVE-2011-2728
published 2012-12-21CVE-2011-2728: The bsd_glob function in the File::Glob module for Perl before 5.14.2 allows context-dependent attackers to cause a denial of service (crash) via a glob…
PriorityP414medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
1.40%
69.6th percentile
The bsd_glob function in the File::Glob module for Perl before 5.14.2 allows context-dependent attackers to cause a denial of service (crash) via a glob expression with the GLOB_ALTDIRFUNC flag, which triggers an uninitialized pointer dereference.
Affected
127 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | perl | < perl 5.14.2-1 (bookworm) | perl 5.14.2-1 (bookworm) |
| perl | perl | <= 5.14.1 | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8m64-rq77-cfmc: The bsd_glob function in the File::Glob module for Perl before 5
ghsa_unreviewed·2022-05-17
CVE-2011-2728 [MEDIUM] GHSA-8m64-rq77-cfmc: The bsd_glob function in the File::Glob module for Perl before 5
The bsd_glob function in the File::Glob module for Perl before 5.14.2 allows context-dependent attackers to cause a denial of service (crash) via a glob expression with the GLOB_ALTDIRFUNC flag, which triggers an uninitialized pointer dereference.
OSV
CVE-2011-2728: The bsd_glob function in the File::Glob module for Perl before 5
osv·2012-12-21·CVSS 4.3
CVE-2011-2728 [MEDIUM] CVE-2011-2728: The bsd_glob function in the File::Glob module for Perl before 5
The bsd_glob function in the File::Glob module for Perl before 5.14.2 allows context-dependent attackers to cause a denial of service (crash) via a glob expression with the GLOB_ALTDIRFUNC flag, which triggers an uninitialized pointer dereference.
Red Hat
perl: File:: Glob bsd_glob() crash with certain glob flags
vendor_redhat·2011-09-26·CVSS 4.3
CVE-2011-2728 [MEDIUM] perl: File:: Glob bsd_glob() crash with certain glob flags
perl: File:: Glob bsd_glob() crash with certain glob flags
The bsd_glob function in the File::Glob module for Perl before 5.14.2 allows context-dependent attackers to cause a denial of service (crash) via a glob expression with the GLOB_ALTDIRFUNC flag, which triggers an uninitialized pointer dereference.
Statement: Red Hat does not consider this flaw to be a security issue. The flags argument passed to the bsd_glob() function is solely under the control of the script author.
Package: perl (Red Hat Enterprise Linux 4) - Not affected
Package: perl (Red Hat Enterprise Linux 5) - Not affected
Package: perl (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2011-2728: perl - The bsd_glob function in the File::Glob module for Perl before 5.14.2 allows con...
vendor_debian·2011·CVSS 4.3
CVE-2011-2728 [MEDIUM] CVE-2011-2728: perl - The bsd_glob function in the File::Glob module for Perl before 5.14.2 allows con...
The bsd_glob function in the File::Glob module for Perl before 5.14.2 allows context-dependent attackers to cause a denial of service (crash) via a glob expression with the GLOB_ALTDIRFUNC flag, which triggers an uninitialized pointer dereference.
Scope: local
bookworm: resolved (fixed in 5.14.2-1)
bullseye: resolved (fixed in 5.14.2-1)
forky: resolved (fixed in 5.14.2-1)
sid: resolved (fixed in 5.14.2-1)
trixie: resolved (fixed in 5.14.2-1)
No detection rules found.
No public exploits indexed.
http://cpansearch.perl.org/src/FLORA/perl-5.14.2/pod/perldelta.podhttp://lists.fedoraproject.org/pipermail/package-announce/2011-November/069752.htmlhttp://perl5.git.perl.org/perl.git/commit/1af4051e077438976a4c12a0622feaf6715bec77http://secunia.com/advisories/46172http://www.securityfocus.com/bid/49858https://blogs.oracle.com/sunsecurity/entry/cve_2011_2728_denial_of1https://bugzilla.redhat.com/show_bug.cgi?id=742987http://cpansearch.perl.org/src/FLORA/perl-5.14.2/pod/perldelta.podhttp://lists.fedoraproject.org/pipermail/package-announce/2011-November/069752.htmlhttp://perl5.git.perl.org/perl.git/commit/1af4051e077438976a4c12a0622feaf6715bec77http://secunia.com/advisories/46172http://www.securityfocus.com/bid/49858https://blogs.oracle.com/sunsecurity/entry/cve_2011_2728_denial_of1https://bugzilla.redhat.com/show_bug.cgi?id=742987
2012-12-21
Published