ePerl Foreign Code Execution Vulnerability
BID:2912
Info
ePerl Foreign Code Execution Vulnerability
| Bugtraq ID: | 2912 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2001 12:00AM |
| Updated: | Jun 19 2001 12:00AM |
| Credit: | Reported to Bugtraq by David Madison <[email protected]> on June 19, 2001. |
| Vulnerable: |
Ralf S. Engelschall ePerl 2.2.14 Ralf S. Engelschall ePerl 2.2.13 Ralf S. Engelschall ePerl 2.2.12 Ralf S. Engelschall ePerl 2.2.11 Ralf S. Engelschall ePerl 2.2.10 Ralf S. Engelschall ePerl 2.2.9 Ralf S. Engelschall ePerl 2.2.8 Ralf S. Engelschall ePerl 2.2.7 Ralf S. Engelschall ePerl 2.2.6 Ralf S. Engelschall ePerl 2.2.5 Ralf S. Engelschall ePerl 2.2.4 Ralf S. Engelschall ePerl 2.2.3 Ralf S. Engelschall ePerl 2.2.2 Ralf S. Engelschall ePerl 2.2.1 Ralf S. Engelschall ePerl 2.2 Ralf S. Engelschall ePerl 2.1.2 Ralf S. Engelschall ePerl 2.1.1 Ralf S. Engelschall ePerl 2.1 Ralf S. Engelschall ePerl 2.0.3 Ralf S. Engelschall ePerl 2.0.2 Ralf S. Engelschall ePerl 2.0.1 Ralf S. Engelschall ePerl 2.0 |
| Not Vulnerable: | |
Discussion
ePerl Foreign Code Execution Vulnerability
ePerl is a multipurpose Perl filter and interpreter program for Unix systems.
The ePerl preprocessor contains an input validation error. The preprocessor allows foreign data to be "safely" included using the 'sinclude' directive.
The problem occurs when a file referenced by a 'sinclude' directive contains a 'include' directive; the contents of the file referred to by the second directive will be loaded and executed.
ePerl is a multipurpose Perl filter and interpreter program for Unix systems.
The ePerl preprocessor contains an input validation error. The preprocessor allows foreign data to be "safely" included using the 'sinclude' directive.
The problem occurs when a file referenced by a 'sinclude' directive contains a 'include' directive; the contents of the file referred to by the second directive will be loaded and executed.
Solution / Fix
ePerl Foreign Code Execution Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.