Perl Safe Module 'reval()' and 'rdo()' Restriction-Bypass Vulnerabilities
BID:40302
Info
Perl Safe Module 'reval()' and 'rdo()' Restriction-Bypass Vulnerabilities
| Bugtraq ID: | 40302 |
| Class: | Design Error |
| CVE: |
CVE-2010-1168 CVE-2010-1974 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 08 2010 12:00AM |
| Updated: | Jul 05 2016 10:09PM |
| Credit: | Rafael Garcia-Suarez |
| Vulnerable: |
VMWare ESX Server 3.0.3 VMWare ESX Server 4.1 VMWare ESX Server 4.0 VMWare ESX Server 3.5 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise 11 SuSE SUSE Linux Enterprise 10 SP3 Sun Solaris 9_x86 Sun Solaris 9_sparc Sun Solaris 10_x86 Sun Solaris 10_sparc S.u.S.E. openSUSE 11.2 S.u.S.E. openSUSE 11.1 rPath rPath Linux 2 rPath Appliance Platform Linux Service 2 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Enterprise Linux Desktop version 4 RedHat Desktop 3.0 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux AS 3 Red Hat Enterprise Linux 5 Server Pardus Linux 2009 0 Mandriva Linux Mandrake 2010.0 x86_64 Mandriva Linux Mandrake 2010.0 Mandriva Linux Mandrake 2009.1 x86_64 Mandriva Linux Mandrake 2009.1 Mandriva Linux Mandrake 2009.0 x86_64 Mandriva Linux Mandrake 2009.0 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 Larry Wall Perl 5.10.1 Larry Wall Perl 5.10 Larry Wall Perl 5.9.3 Larry Wall Perl 5.9.2 Larry Wall Perl 5.8.8 Larry Wall Perl 5.8.7 Larry Wall Perl 5.8.6 Larry Wall Perl 5.8.5 Larry Wall Perl 5.8.4 -5 Larry Wall Perl 5.8.4 -4 Larry Wall Perl 5.8.4 -3 Larry Wall Perl 5.8.4 -2.3 Larry Wall Perl 5.8.4 -2 Larry Wall Perl 5.8.4 -1 Larry Wall Perl 5.8.4 Larry Wall Perl 5.8.3 Larry Wall Perl 5.8.1 Larry Wall Perl 5.8 .0-88.3 Larry Wall Perl 5.8 Larry Wall Perl 5.6.1 Larry Wall Perl 5.6 Larry Wall Perl 5.0 05_003 Larry Wall Perl 5.0 05 Larry Wall Perl 5.0 04_05 Larry Wall Perl 5.0 04_04 Larry Wall Perl 5.0 04 Larry Wall Perl 5.0 03 Larry Wall Perl 5.12 Larry Wall Perl 5.10 Gentoo Linux F5 Enterprise Manager 2.2 Avaya Voice Portal 5.1 Avaya Voice Portal 4.1 SP2 Avaya Voice Portal 4.1 SP1 Avaya Voice Portal 4.1 Avaya Voice Portal 4.0 Avaya Proactive Contact 4.1.2 Avaya Proactive Contact 4.1.1 Avaya Proactive Contact 4.1 Avaya Proactive Contact 4.0 Avaya Messaging Storage Server MM3.0 Avaya Messaging Storage Server 5.2 Avaya Messaging Storage Server 5.1 Avaya Messaging Storage Server 5.0 Avaya Messaging Storage Server 4.0 Avaya Messaging Storage Server 3.1 SP1 Avaya Messaging Storage Server 3.1 Avaya Messaging Storage Server 2.0 Avaya Messaging Storage Server 1.0 Avaya Messaging Storage Server Avaya Message Networking MN 3.1 Avaya Message Networking 5.2 Avaya Message Networking 3.1 Avaya Message Networking Avaya Meeting Exchange 5.0 .0.52 Avaya Meeting Exchange 5.2 SP1 Avaya Meeting Exchange 5.2 Avaya Meeting Exchange 5.1 SP1 Avaya Meeting Exchange 5.1 Avaya Meeting Exchange 5.0 SP2 Avaya Meeting Exchange 5.0 SP1 Avaya Meeting Exchange 5.0 Avaya Intuity AUDIX LX R1.1 Avaya Intuity AUDIX LX 2.0 SP2 Avaya Intuity AUDIX LX 2.0 SP1 Avaya Intuity AUDIX LX 2.0 Avaya Intuity AUDIX LX 1.0 Avaya Aura SIP Enablement Services 5.2.1 Avaya Aura SIP Enablement Services 3.1.1 Avaya Aura SIP Enablement Services 3.1 Avaya Aura SIP Enablement Services 5.2 Avaya Aura SIP Enablement Services 5.1 Avaya Aura SIP Enablement Services 5.0 Avaya Aura SIP Enablement Services 4.0 Avaya Aura SIP Enablement Services 3.1 Avaya Aura SIP Enablement Services 3.0 Avaya Aura Communication Manager 5.2 Avaya Aura Communication Manager 5.1 Avaya Aura Communication Manager 4.0 Avaya Aura Communication Manager 4.0 Avaya Aura Application Enablement Services 4.2.2 Avaya Aura Application Enablement Services 4.2.1 Avaya Aura Application Enablement Services 4.0.1 Avaya Aura Application Enablement Services 4.2 Avaya Aura Application Enablement Services 4.1 Avaya Aura Application Enablement Services 4.0 |
| Not Vulnerable: |
Larry Wall Perl 5.12.1 F5 Enterprise Manager 2.3 |
Discussion
Perl Safe Module 'reval()' and 'rdo()' Restriction-Bypass Vulnerabilities
The Perl Safe module is prone to multiple restriction-bypass vulnerabilities. Successful exploits could allow an attacker to execute arbitrary Perl code outside of the restricted root.
Versions prior to Safe 2.25 are vulnerable.
The Perl Safe module is prone to multiple restriction-bypass vulnerabilities. Successful exploits could allow an attacker to execute arbitrary Perl code outside of the restricted root.
Versions prior to Safe 2.25 are vulnerable.
Exploit / POC
Perl Safe Module 'reval()' and 'rdo()' Restriction-Bypass Vulnerabilities
To exploit this issue, an attacker can use readily available tools.
To exploit this issue, an attacker can use readily available tools.
Solution / Fix
Perl Safe Module 'reval()' and 'rdo()' Restriction-Bypass Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2008.0
Mandriva Linux Mandrake 2009.0 x86_64
Mandriva Linux Mandrake 2009.1 x86_64
MandrakeSoft Enterprise Server 5
Mandriva Linux Mandrake 2009.0
Mandriva Linux Mandrake 2008.0 x86_64
MandrakeSoft Corporate Server 4.0 x86_64
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2008.0
-
Mandriva perl-doc-5.8.8-12.3mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva perl-suid-5.8.8-12.3mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2009.0 x86_64
-
Mandriva perl-5.10.0-25.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva perl-base-5.10.0-25.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva perl-devel-5.10.0-25.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva perl-doc-5.10.0-25.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva perl-suid-5.10.0-25.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2009.1 x86_64
-
Mandriva perl-5.10.0-25.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva perl-base-5.10.0-25.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva perl-devel-5.10.0-25.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva perl-doc-5.10.0-25.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva perl-suid-5.10.0-25.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Enterprise Server 5
-
Mandriva perl-5.10.0-25.2mdvmes5.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva perl-base-5.10.0-25.2mdvmes5.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva perl-devel-5.10.0-25.2mdvmes5.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva perl-doc-5.10.0-25.2mdvmes5.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva perl-suid-5.10.0-25.2mdvmes5.1.i586.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2009.0
-
Mandriva perl-5.10.0-25.2mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva perl-base-5.10.0-25.2mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva perl-devel-5.10.0-25.2mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva perl-doc-5.10.0-25.2mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva perl-suid-5.10.0-25.2mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.0 x86_64
-
Mandriva perl-5.8.8-12.3mdv2008.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva perl-base-5.8.8-12.3mdv2008.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva perl-devel-5.8.8-12.3mdv2008.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva perl-doc-5.8.8-12.3mdv2008.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva perl-suid-5.8.8-12.3mdv2008.0.x86_64.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 4.0 x86_64
-
Mandriva perl-5.8.7-3.6.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva perl-base-5.8.7-3.6.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva perl-devel-5.8.7-3.6.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva perl-doc-5.8.7-3.6.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva perl-suid-5.8.7-3.6.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/
References
Perl Safe Module 'reval()' and 'rdo()' Restriction-Bypass Vulnerabilities
References:
References:
- Bug 576508 - (CVE-2010-1168) CVE-2010-1168 perl Safe: Intended restriction bypas (Jan Lieskovsky )
- CVE-2010-1168 Vulnerability in Safe Perl Module (Safe.pm) for Perl 5.8 (Oracle)
- CVE-2010-1168 vulnerability in Safe.pm Perl 5.6.1 module (Oracle)
- CVE-2010-1974 reject request (dupe of CVE-2010-1168) and CVE-2010-1447 descripti (Jan Lieskovsky)
- Enterprise Manager Homepage (F5)
- New Safe.pm fixes security hole (Rafael Garcia-Suarez)
- Release Note: Enterprise Manager version 2.3.0 (F5)
- Safe 2.27 Changelog (Rafael Garcia-Suarez)
- Safe Homepage (Rafael Garcia-Suarez)
- 2016-04 Security Bulletin: CTP Series: Multiple vulnerabilities in CTP Series (Juniper)
- ASA-2010-172 perl security update (RHSA-2010-0457) (Avaya)