CVE-2013-4407
CVE-2013-4407
HTTP::Body::Multipart in the HTTP-Body module for Perl (1.07 through 1.22, before 1.23) uses the part of the uploaded file's name after the first "." character as the suffix of a temporary file, which makes it easier for remote attackers to conduct attacks by leveraging subsequent behavior that may assume the suffix is well-formed.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=721634http://git.shadowcat.co.uk/gitweb/gitweb.cgi?p=catagits/HTTP-Body.git%3Ba=commit%3Bh=13ac5b23c083bc56e32dd706ca02fca292bd2161http://git.shadowcat.co.uk/gitweb/gitweb.cgi?p=catagits/HTTP-Body.git%3Ba=commit%3Bh=cc75c886256f187cda388641931e8dafad6c2346http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00018.htmlhttps://metacpan.org/release/GETTY/HTTP-Body-1.23/https://www.openwall.com/lists/oss-security/2024/04/07/1http://www.debian.org/security/2013/dsa-2801http://www.openwall.com/lists/oss-security/2024/04/07/1