CVE-2010-1447
Summary
| CVE | CVE-2010-1447 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-05-19 18:30:03 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The Safe (aka Safe.pm) module 2.26, and certain earlier versions, for Perl, as used in PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2, allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving subroutine references and delayed execution. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Postgresql | Postgresql | 7.4 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.1 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.10 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.11 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.12 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.13 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.14 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.15 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.16 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.17 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.18 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.19 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.2 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.20 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.21 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.22 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.23 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.24 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.25 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.26 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.27 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.28 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.3 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.4 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.5 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.6 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.7 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.8 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.9 | All | All | All |
| Application | Postgresql | Postgresql | 8.0 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.0 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.1 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.10 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.11 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.12 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.13 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.14 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.15 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.16 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.17 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.18 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.19 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.20 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.21 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.22 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.23 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.24 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.4 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.5 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.6 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.7 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.8 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.9 | All | All | All |
| Application | Postgresql | Postgresql | 8.1 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.0 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.1 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.10 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.11 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.12 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.13 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.14 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.15 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.16 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.17 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.18 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.19 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.20 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.4 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.5 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.6 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.7 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.8 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.9 | All | All | All |
| Application | Postgresql | Postgresql | 8.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.1 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.10 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.11 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.12 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.13 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.14 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.15 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.16 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.4 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.5 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.6 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.7 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.8 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.9 | All | All | All |
| Application | Postgresql | Postgresql | 8.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.1 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.10 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.4 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.5 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.6 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.7 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.8 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.9 | All | All | All |
| Application | Postgresql | Postgresql | 8.4 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.1 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.3 | All | All | All |
| Application | Postgresql | Postgresql | 9.0.0 | beta1 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat update for perl - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE-2010-1447 | af854a3a-2127-422b-91ae-364da2661108 | security-tracker.debian.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Bug 588269 – CVE-2010-1447 perl: Safe restriction bypass when reference to subroutine in compartment is called from outside | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Patch, Vendor Advisory |
| mandriva.com | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| CVE-2010-1447 | af854a3a-2127-422b-91ae-364da2661108 | bugs.launchpad.net | |
| Debian -- Security Information -- DSA-2267-1 perl | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Perl Safe Module 'reval()' and 'rdo()' CVE-2010-1447 Restriction-Bypass Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| PostgreSQL: News: 2010-05-17 PostgreSQL Security Update | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| SecurityTracker.com Archives - PostgreSQL Flaws in Safe.pm and PL/Perl Let Remote Authenticated Users Gain Elevated Privileges | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| oss-security - CVE-2010-1974 reject request (dupe of CVE-2010-1168) and CVE-2010-1447 description modification request | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Red Hat update for perl - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Juniper Networks - 2015-10 Security Bulletin: CTPView: Multiple Vulnerabilities in CTPView | af854a3a-2127-422b-91ae-364da2661108 | kb.juniper.net | |
| mandriva.com | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| PostgreSQL Two Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| osvdb.org/64756 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.