CVE-2024-55918

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-55918
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-55918.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-55918
Related
Published
2024-12-13T07:15:04Z
Modified
2024-12-17T20:15:23Z
Summary
[none]
Details

An issue was discovered in the Graphics::ColorNames package before 3.2.0 for Perl. There is an ambiguity between modules and filenames that can lead to HTML injection by an attacker who can create a file in the current working directory.

References

Affected packages

Debian:11 / libgraphics-colornames-perl

Package

Name
libgraphics-colornames-perl
Purl
pkg:deb/debian/libgraphics-colornames-perl?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.5.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / libgraphics-colornames-perl

Package

Name
libgraphics-colornames-perl
Purl
pkg:deb/debian/libgraphics-colornames-perl?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.5.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / libgraphics-colornames-perl

Package

Name
libgraphics-colornames-perl
Purl
pkg:deb/debian/libgraphics-colornames-perl?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.5.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}