CVE-2012-6329
Summary
| CVE | CVE-2012-6329 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-01-04 21:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly handle backslashes and fully qualified method names during compilation of bracket notation, which allows context-dependent attackers to execute arbitrary commands via crafted input to an application that accepts translation strings from users, as demonstrated by the TWiki application before 5.1.3, and the Foswiki application 1.0.x through 1.0.10 and 1.1.x through 1.1.6. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Perl | Perl | 5.10 | All | All | All |
| Application | Perl | Perl | 5.10.0 | All | All | All |
| Application | Perl | Perl | 5.10.0 | rc1 | All | All |
| Application | Perl | Perl | 5.10.0 | rc2 | All | All |
| Application | Perl | Perl | 5.10.1 | All | All | All |
| Application | Perl | Perl | 5.10.1 | rc1 | All | All |
| Application | Perl | Perl | 5.10.1 | rc2 | All | All |
| Application | Perl | Perl | 5.11.0 | All | All | All |
| Application | Perl | Perl | 5.11.1 | All | All | All |
| Application | Perl | Perl | 5.11.2 | All | All | All |
| Application | Perl | Perl | 5.11.3 | All | All | All |
| Application | Perl | Perl | 5.11.4 | All | All | All |
| Application | Perl | Perl | 5.11.5 | All | All | All |
| Application | Perl | Perl | 5.12.0 | All | All | All |
| Application | Perl | Perl | 5.12.0 | rc0 | All | All |
| Application | Perl | Perl | 5.12.0 | rc1 | All | All |
| Application | Perl | Perl | 5.12.0 | rc2 | All | All |
| Application | Perl | Perl | 5.12.0 | rc3 | All | All |
| Application | Perl | Perl | 5.12.0 | rc4 | All | All |
| Application | Perl | Perl | 5.12.0 | rc5 | All | All |
| Application | Perl | Perl | 5.12.1 | All | All | All |
| Application | Perl | Perl | 5.12.1 | rc1 | All | All |
| Application | Perl | Perl | 5.12.1 | rc2 | All | All |
| Application | Perl | Perl | 5.12.2 | All | All | All |
| Application | Perl | Perl | 5.12.2 | rc1 | All | All |
| Application | Perl | Perl | 5.12.3 | All | All | All |
| Application | Perl | Perl | 5.12.3 | rc1 | All | All |
| Application | Perl | Perl | 5.12.3 | rc2 | All | All |
| Application | Perl | Perl | 5.12.3 | rc3 | All | All |
| Application | Perl | Perl | 5.13.0 | All | All | All |
| Application | Perl | Perl | 5.13.1 | All | All | All |
| Application | Perl | Perl | 5.13.10 | All | All | All |
| Application | Perl | Perl | 5.13.11 | All | All | All |
| Application | Perl | Perl | 5.13.2 | All | All | All |
| Application | Perl | Perl | 5.13.3 | All | All | All |
| Application | Perl | Perl | 5.13.4 | All | All | All |
| Application | Perl | Perl | 5.13.5 | All | All | All |
| Application | Perl | Perl | 5.13.6 | All | All | All |
| Application | Perl | Perl | 5.13.7 | All | All | All |
| Application | Perl | Perl | 5.13.8 | All | All | All |
| Application | Perl | Perl | 5.13.9 | All | All | All |
| Application | Perl | Perl | 5.14.0 | All | All | All |
| Application | Perl | Perl | 5.14.0 | rc1 | All | All |
| Application | Perl | Perl | 5.14.0 | rc2 | All | All |
| Application | Perl | Perl | 5.14.0 | rc3 | All | All |
| Application | Perl | Perl | 5.14.1 | All | All | All |
| Application | Perl | Perl | 5.14.2 | All | All | All |
| Application | Perl | Perl | 5.14.3 | All | All | All |
| Application | Perl | Perl | 5.16.0 | All | All | All |
| Application | Perl | Perl | 5.16.1 | All | All | All |
| Application | Perl | Perl | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityAlert-CVE-2012-6329 < Codev < TWiki | af854a3a-2127-422b-91ae-364da2661108 | twiki.org | |
| TWiki and Foswiki 'MAKETEXT' Variable Multiple Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Oracle VM Server for x86 Bulletin - July 2016 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| Re: security notice: Locale::Maketext « perl5-porters « ActiveState List Archives | af854a3a-2127-422b-91ae-364da2661108 | code.activestate.com | |
| #695224 - perl-modules: Locale::Maketext code injection - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | |
| Bug 884354 – CVE-2012-6329 perl: possible arbitrary code execution via Locale::Maketext | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| perl5.git.perl.org Git - perl.git/commit | af854a3a-2127-422b-91ae-364da2661108 | perl5.git.perl.org | Patch |
| security notice: Locale::Maketext « perl5-porters « ActiveState List Archives | af854a3a-2127-422b-91ae-364da2661108 | code.activestate.com | |
| Support / Security / Advisories / / MDVSA-2013:113 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| perl5.git.perl.org Git | af854a3a-2127-422b-91ae-364da2661108 | perl5.git.perl.org | |
| Foswiki / Mailing Lists | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | |
| oss-security - Re: CVE request: perl-modules | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | |
| USN-2099-1: Perl vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Juniper Networks - 2015-10 Security Bulletin: CTPView: Multiple Vulnerabilities in CTPView | af854a3a-2127-422b-91ae-364da2661108 | kb.juniper.net | |
| 2016-04 Security Bulletin: CTP Series: Multiple vulnerabilities in CTP Series - Juniper Networks | af854a3a-2127-422b-91ae-364da2661108 | kb.juniper.net | |
| Support/Advisories/MGASA-2013-0032 - Mageia wiki | af854a3a-2127-422b-91ae-364da2661108 | wiki.mageia.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.