Safe.PM Unsafe Code Execution Vulnerability
BID:6111
Info
Safe.PM Unsafe Code Execution Vulnerability
| Bugtraq ID: | 6111 |
| Class: | Access Validation Error |
| CVE: |
CVE-2002-1323 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 06 2002 12:00AM |
| Updated: | Jul 11 2009 06:06PM |
| Credit: | Discovery of this vulnerability credited to Andreas Jurenda ([email protected]). |
| Vulnerable: |
Sun Solaris 9_x86 Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Linux 5.0.7 SGI IRIX 6.5.22 SGI IRIX 6.5.21 m SGI IRIX 6.5.21 f SGI IRIX 6.5.20 m SGI IRIX 6.5.20 f SGI IRIX 6.5.19 m SGI IRIX 6.5.19 f SGI IRIX 6.5.19 SGI IRIX 6.5.18 m SGI IRIX 6.5.18 f SGI IRIX 6.5.18 SGI IRIX 6.5.17 m SGI IRIX 6.5.17 f SGI IRIX 6.5.17 SGI IRIX 6.5.16 SGI IRIX 6.5.15 SGI IRIX 6.5.14 SGI IRIX 6.5.13 SGI IRIX 6.5.12 SGI IRIX 6.5.11 SGI IRIX 6.5.10 SGI IRIX 6.5.9 SGI IRIX 6.5.8 SGI IRIX 6.5.7 SGI IRIX 6.5.6 SGI IRIX 6.5.5 SGI IRIX 6.5.4 SGI IRIX 6.5.3 SGI IRIX 6.5.2 SGI IRIX 6.5.1 SGI IRIX 6.5 SCO Unixware 7.1.3 SCO Unixware 7.1.2 SCO Open UNIX 8.0 Safe.pm Safe.pm 2.0 7 Safe.pm Safe.pm 2.0 6 Redhat Linux Advanced Work Station 2.1 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 |
| Not Vulnerable: |
Safe.pm Safe.pm 2.0 9 Safe.pm Safe.pm 2.0 8 |
Discussion
Safe.PM Unsafe Code Execution Vulnerability
When Perl code is executed within a Safe compartment, it cannot access variables outside of the compartment unless the outside code chooses to share the variables with the code inside the compartment.
If code inside a Safe compartment is executed via 'Safe->reval()' twice, it can change its operation mask the second time. This could allow the code to access variables outside the Safe compartment.
When Perl code is executed within a Safe compartment, it cannot access variables outside of the compartment unless the outside code chooses to share the variables with the code inside the compartment.
If code inside a Safe compartment is executed via 'Safe->reval()' twice, it can change its operation mask the second time. This could allow the code to access variables outside the Safe compartment.
Exploit / POC
Safe.PM Unsafe Code Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.