CVE-2011-1487
Summary
| CVE | CVE-2011-1487 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-04-11 18:55:03 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Perl | Perl | 5.10.0 | All | All | All |
| Application | Perl | Perl | 5.10.0 | rc1 | All | All |
| Application | Perl | Perl | 5.10.0 | rc2 | All | All |
| Application | Perl | Perl | 5.10.1 | All | All | All |
| Application | Perl | Perl | 5.10.1 | rc1 | All | All |
| Application | Perl | Perl | 5.10.1 | rc2 | All | All |
| Application | Perl | Perl | 5.11.0 | All | All | All |
| Application | Perl | Perl | 5.11.1 | All | All | All |
| Application | Perl | Perl | 5.11.2 | All | All | All |
| Application | Perl | Perl | 5.11.3 | All | All | All |
| Application | Perl | Perl | 5.11.4 | All | All | All |
| Application | Perl | Perl | 5.11.5 | All | All | All |
| Application | Perl | Perl | 5.12.0 | All | All | All |
| Application | Perl | Perl | 5.12.0 | rc0 | All | All |
| Application | Perl | Perl | 5.12.0 | rc1 | All | All |
| Application | Perl | Perl | 5.12.0 | rc2 | All | All |
| Application | Perl | Perl | 5.12.0 | rc3 | All | All |
| Application | Perl | Perl | 5.12.0 | rc4 | All | All |
| Application | Perl | Perl | 5.12.0 | rc5 | All | All |
| Application | Perl | Perl | 5.12.1 | All | All | All |
| Application | Perl | Perl | 5.12.1 | rc1 | All | All |
| Application | Perl | Perl | 5.12.1 | rc2 | All | All |
| Application | Perl | Perl | 5.12.2 | All | All | All |
| Application | Perl | Perl | 5.12.2 | rc1 | All | All |
| Application | Perl | Perl | 5.12.3 | All | All | All |
| Application | Perl | Perl | 5.12.3 | rc1 | All | All |
| Application | Perl | Perl | 5.12.3 | rc2 | All | All |
| Application | Perl | Perl | 5.12.3 | rc3 | All | All |
| Application | Perl | Perl | 5.13.0 | All | All | All |
| Application | Perl | Perl | 5.13.1 | All | All | All |
| Application | Perl | Perl | 5.13.10 | All | All | All |
| Application | Perl | Perl | 5.13.11 | All | All | All |
| Application | Perl | Perl | 5.13.2 | All | All | All |
| Application | Perl | Perl | 5.13.3 | All | All | All |
| Application | Perl | Perl | 5.13.4 | All | All | All |
| Application | Perl | Perl | 5.13.5 | All | All | All |
| Application | Perl | Perl | 5.13.6 | All | All | All |
| Application | Perl | Perl | 5.13.7 | All | All | All |
| Application | Perl | Perl | 5.13.8 | All | All | All |
| Application | Perl | Perl | 5.13.9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fedora update for perl - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Support / Security / Advisories / / MDVSA-2011:091 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2011:009 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Bug 692898 – CVE-2011-1487 perl: lc(), uc() routines are laundering tainted data | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Exploit, Patch |
| [SECURITY] Fedora 14 Update: perl-5.12.3-143.fc14 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| oss-security - CVE Request -- perl -- lc(), uc() routines are laundering tainted data | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Exploit, Patch |
| Function lc() is laundering tainted data in newer perls, contrary to docs · Issue #11219 · Perl/perl5 · GitHub | af854a3a-2127-422b-91ae-364da2661108 | rt.perl.org | Exploit |
| Malformed Request | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| perl5.git.perl.org Git - perl.git/commit | af854a3a-2127-422b-91ae-364da2661108 | perl5.git.perl.org | Patch |
| oss-security - Re: CVE Request -- perl -- lc(), uc() routines are laundering tainted data | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Exploit, Patch |
| 692844 – lc launders tainted flag | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Debian -- Security Information -- DSA-2265-1 perl | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Perl "uc()", "lc()", "lcfirst()", and "ucfirst()" Taint Mode Bypass Weakness - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| [SECURITY] Fedora 15 Update: perl-5.12.3-156.fc15 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.