CVE-2008-7319
Summary
| CVE | CVE-2008-7319 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-11-07 21:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | The Net::Ping::External extension through 0.15 for Perl does not properly sanitize arguments (e.g., invalid hostnames) containing shell metacharacters before use of backticks in External.pm, allowing for shell command injection and arbitrary command execution if untrusted input is used. |
Risk And Classification
Primary CVSS: v3.0 9.8 CRITICAL from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-77 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 9.8 | CRITICAL | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 10 | AV:N/AC:L/Au:N/C:C/I:C/A:C |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Net-ping-external Project | Net-ping-external | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - Net::Ping::External command injections | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Issue Tracking, Mailing List, Patch, Third Party Advisory |
| #881097 - libnet-ping-external-perl: CVE-2008-7319: command injection via crafted arguments - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | Issue Tracking, Patch, Third Party Advisory |
| matthias.sdfeu.org/devel/net-ping-external-cmd-injection.patch | af854a3a-2127-422b-91ae-364da2661108 | matthias.sdfeu.org | Issue Tracking, Patch, Third Party Advisory |
| Bug #33230 for Net-Ping-External: shell exploit and resolv error | af854a3a-2127-422b-91ae-364da2661108 | rt.cpan.org | Issue Tracking, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.