MGASA-2013-0352

Source
https://advisories.mageia.org/MGASA-2013-0352.html
Import Source
https://advisories.mageia.org/MGASA-2013-0352.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2013-0352
Related
Published
2013-11-22T19:20:13Z
Modified
2013-11-22T19:20:03Z
Summary
Updated perl-HTTP-Body packages fix CVE-2013-4407
Details

Updated perl-HTTP-Body package fixes security vulnerability:

Jonathan Dolle reported a design error in HTTP::Body, a Perl module for processing data from HTTP POST requests. The HTTP body multipart parser creates temporary files which preserve the suffix of the uploaded file. An attacker able to upload files to a service that uses HTTP::Body::Multipart could potentially execute commands on the server if these temporary filenames are used in subsequent commands without further checks (CVE-2013-4407).

References
Credits

Affected packages

Mageia:3 / perl-HTTP-Body

Package

Name
perl-HTTP-Body
Purl
pkg:rpm/mageia/perl-HTTP-Body?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.170.0-2.1.mga3

Ecosystem specific

{
    "section": "core"
}

Mageia:2 / perl-HTTP-Body

Package

Name
perl-HTTP-Body
Purl
pkg:rpm/mageia/perl-HTTP-Body?distro=mageia-2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.150.0-1.1.mga2

Ecosystem specific

{
    "section": "core"
}