UBUNTU-CVE-2008-7319

Source
https://ubuntu.com/security/CVE-2008-7319
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2008/UBUNTU-CVE-2008-7319.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2008-7319
Upstream
  • CVE-2008-7319
Published
2017-11-07T21:29:00Z
Modified
2025-10-24T04:44:50Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

The Net::Ping::External extension through 0.15 for Perl does not properly sanitize arguments (e.g., invalid hostnames) containing shell metacharacters before use of backticks in External.pm, allowing for shell command injection and arbitrary command execution if untrusted input is used.

References

Affected packages

Ubuntu:16.04:LTS / libnet-ping-external-perl

Package

Name
libnet-ping-external-perl
Purl
pkg:deb/ubuntu/libnet-ping-external-perl@0.13-1?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.13-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libnet-ping-external-perl",
            "binary_version": "0.13-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2008/UBUNTU-CVE-2008-7319.json"