CVE-2013-1437
published 2020-01-28CVE-2013-1437: Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute arbitrary Perl code via the $Version…
PriorityP359critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.94%
85.6th percentile
Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute arbitrary Perl code via the $Version value.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libmodule-metadata-perl | < libmodule-metadata-perl 1.000015-1 (bookworm) | libmodule-metadata-perl 1.000015-1 (bookworm) |
| debian | perl | < libmodule-metadata-perl 1.000015-1 (bookworm) | libmodule-metadata-perl 1.000015-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| module-metadata_project | module-metadata | < 1.000015 | 1.000015 |
| perl | perl | >= 0 < 5.18.1-2 | 5.18.1-2 |
| perl | perl | >= 0 < 5.18.1-2 | 5.18.1-2 |
| perl | perl | >= 0 < 5.18.1-2 | 5.18.1-2 |
| perl | perl | >= 0 < 5.18.1-2 | 5.18.1-2 |
| perl_toolchain_gang | module-metadata | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-86v9-w7h5-78qj: Eval injection vulnerability in the Module-Metadata module before 1
ghsa_unreviewed·2022-05-05
CVE-2013-1437 [HIGH] GHSA-86v9-w7h5-78qj: Eval injection vulnerability in the Module-Metadata module before 1
Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute arbitrary Perl code via the $Version value.
OSV
CVE-2013-1437: Eval injection vulnerability in the Module-Metadata module before 1
osv·2020-01-28·CVSS 9.8
CVE-2013-1437 [CRITICAL] CVE-2013-1437: Eval injection vulnerability in the Module-Metadata module before 1
Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute arbitrary Perl code via the $Version value.
Red Hat
perl-Module-Metadata: incorrectly documents that it does not execute unsafe code
vendor_redhat·2013-08-21·CVSS 9.8
CVE-2013-1437 [CRITICAL] perl-Module-Metadata: incorrectly documents that it does not execute unsafe code
perl-Module-Metadata: incorrectly documents that it does not execute unsafe code
Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute arbitrary Perl code via the $Version value.
Package: perl-Module-Metadata (Red Hat Enterprise Linux 7) - Not affected
Package: perl516-perl-Module-Metadata (Red Hat Software Collections) - Affected
Debian
CVE-2013-1437: libmodule-metadata-perl - Eval injection vulnerability in the Module-Metadata module before 1.000015 for P...
vendor_debian·2013·CVSS 9.8
CVE-2013-1437 [CRITICAL] CVE-2013-1437: libmodule-metadata-perl - Eval injection vulnerability in the Module-Metadata module before 1.000015 for P...
Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute arbitrary Perl code via the $Version value.
Scope: local
bookworm: resolved (fixed in 1.000015-1)
bullseye: resolved (fixed in 1.000015-1)
forky: resolved (fixed in 1.000015-1)
sid: resolved (fixed in 1.000015-1)
trixie: resolved (fixed in 1.000015-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1437 perl-Module-Metadata: incorrectly documents that it does not execute unsafe code [fedora-all]
bugzilla·2013-08-21·CVSS 9.8
CVE-2013-1437 [CRITICAL] CVE-2013-1437 perl-Module-Metadata: incorrectly documents that it does not execute unsafe code [fedora-all]
CVE-2013-1437 perl-Module-Metadata: incorrectly documents that it does not execute unsafe code [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available
Bugzilla
CVE-2013-1437 perl-Module-Metadata: incorrectly documents that it does not execute unsafe code
bugzilla·2013-08-12·CVSS 9.8
CVE-2013-1437 [CRITICAL] CVE-2013-1437 perl-Module-Metadata: incorrectly documents that it does not execute unsafe code
CVE-2013-1437 perl-Module-Metadata: incorrectly documents that it does not execute unsafe code
It was reported that the perl Module::Metadata module incorrectly claimed that it would gather metadata about a .pm file without executing unsafe code. However, when Module::Metadata determines the version of a module, it can extract a small amount of code (if present in the $Version variable assignment) and evaluates it, which can lead to the execution of arbitrary code (the same code that module would execute to obtain the value of $Version).
This behaviour is intended and known by the authors of the module, the only issue here is with the claim of "without executing unsafe code" and with not making this behaviour clearer in the documentation. The authors intend to remove this mis-statement a
Bugzilla
CVE-2013-2102 Gatein: JGroups configurations enable diagnostics without authentication
bugzilla·2013-05-16·CVSS 3.3
CVE-2013-2102 [LOW] CVE-2013-2102 Gatein: JGroups configurations enable diagnostics without authentication
CVE-2013-2102 Gatein: JGroups configurations enable diagnostics without authentication
When a JGroups channel is started, the JGroups diagnostics service will be enabled by default with no authentication. This service is exposed via IP multicast. An attacker on an adjacent network can exploit this flaw only to read diagnostics information (information disclosure).
Discussion:
Acknowledgements:
This issue was discovered by Red Hat.
---
This issue has been addressed in following products:
Red Hat JBoss Portal 6.1.0
Via RHSA-2013:1437 https://rhn.redhat.com/errata/RHSA-2013-1437.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-August/114904.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-August/114912.htmlhttps://metacpan.org/changes/distribution/Module-Metadatahttp://lists.fedoraproject.org/pipermail/package-announce/2013-August/114904.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-August/114912.htmlhttps://metacpan.org/changes/distribution/Module-Metadata
2020-01-28
Published