'Compress::Raw::Bzip2' Perl Module Remote Code Execution Vulnerability
BID:36082
Info
'Compress::Raw::Bzip2' Perl Module Remote Code Execution Vulnerability
| Bugtraq ID: | 36082 |
| Class: | Design Error |
| CVE: |
CVE-2009-1884 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 18 2009 12:00AM |
| Updated: | Dec 01 2009 10:05PM |
| Credit: | The vendor reported the issue. |
| Vulnerable: |
Mandriva Linux Mandrake 2009.1 x86_64 Mandriva Linux Mandrake 2009.1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Gentoo Linux Compress::Raw::Bzip2 Compress::Raw::Bzip2 2.017 Activestate ActivePerl 5.10.1 |
| Not Vulnerable: |
Compress::Raw::Bzip2 Compress::Raw::Bzip2 2.019 Activestate ActivePerl 5.10.1 build 1006 |
Discussion
'Compress::Raw::Bzip2' Perl Module Remote Code Execution Vulnerability
The 'Compress::Raw::Bzip2' Perl module is prone to a remote code-execution vulnerability.
Successful exploits may allow remote attackers to execute arbitrary code or cause denial-of-service conditions in applications that use the vulnerable module.
Versions prior to 'Compress::Raw::Bzip2' 2.019 are affected.
The 'Compress::Raw::Bzip2' Perl module is prone to a remote code-execution vulnerability.
Successful exploits may allow remote attackers to execute arbitrary code or cause denial-of-service conditions in applications that use the vulnerable module.
Versions prior to 'Compress::Raw::Bzip2' 2.019 are affected.
Exploit / POC
'Compress::Raw::Bzip2' Perl Module Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
'Compress::Raw::Bzip2' Perl Module Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references for details.
Mandriva Linux Mandrake 2009.1
MandrakeSoft Enterprise Server 5 x86_64
Mandriva Linux Mandrake 2009.1 x86_64
MandrakeSoft Enterprise Server 5
Compress::Raw::Bzip2 Compress::Raw::Bzip2 2.017
Solution:
Updates are available. Please see the references for details.
Mandriva Linux Mandrake 2009.1
-
Mandriva perl-Compress-Raw-Bzip2-2.015-2.1mdv2009.1.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva perl-Compress-Raw-Bzip2-2.015-1.1mdvmes5.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2009.1 x86_64
-
Mandriva perl-Compress-Raw-Bzip2-2.015-2.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Enterprise Server 5
-
Mandriva perl-Compress-Raw-Bzip2-2.015-1.1mdvmes5.i586.rpm
http://www.mandriva.com/en/download/
Compress::Raw::Bzip2 Compress::Raw::Bzip2 2.017
-
Compress::Raw::Bzip2 Compress-Raw-Bzip2-2.019.tar.gz
http://search.cpan.org/CPAN/authors/id/P/PM/PMQS/Compress-Raw-Bzip2-2. 019.tar.gz
References
'Compress::Raw::Bzip2' Perl Module Remote Code Execution Vulnerability
References:
References:
- ActiveState announces ActivePerl 5.10.1 build 1006 (Activestate)
- Compress-Raw-Bzip2 Homepage (Compress-Raw-Bzip2)
- Compress-Raw-Bzip2-2.020: Off-by-one buffer overflow (Gentoo)