Description
Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of safe compartments in (1) Safe::reval or (2) Safe::rdo using a redefined @_ variable, which is not reset between successive calls.
Affected products
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / linux_advanced_workstation2.1 – 2.1
- safe.pm / safe.pm2.0_6 – 2.0_6
- safe.pm / safe.pm2.0_7 – 2.0_7
- sco / open_unix8.0 – 8.0
- sco / unixware7.1.2 – 7.1.2
- sco / unixware7.1.3 – 7.1.3
- sgi / irix6.5.11 – 6.5.11
- sgi / irix6.5.12 – 6.5.12
- sgi / irix6.5.13 – 6.5.13
- sgi / irix6.5.14 – 6.5.14
- sgi / irix6.5.15 – 6.5.15
- sgi / irix6.5.16 – 6.5.16
- sgi / irix6.5.17 – 6.5.17
- sgi / irix6.5.17f – 6.5.17f
- sgi / irix6.5.17m – 6.5.17m
- sgi / irix6.5.18 – 6.5.18
- sgi / irix6.5.18f – 6.5.18f
- sgi / irix6.5.18m – 6.5.18m
- sgi / irix6.5.19 – 6.5.19
- sgi / irix6.5.19f – 6.5.19f
- sgi / irix6.5.19m – 6.5.19m
- sgi / irix6.5.20f – 6.5.20f
- sgi / irix6.5.21f – 6.5.21f
- sgi / irix6.5.21m – 6.5.21m
- sgi / irix6.5.22 – 6.5.22
- sgi / irix6.5.20m – 6.5.20m
- sgi / irix6.5 – 6.5
- sgi / irix6.5.1 – 6.5.1
- sgi / irix6.5.2 – 6.5.2
- sgi / irix6.5.3 – 6.5.3
- sgi / irix6.5.4 – 6.5.4
- sgi / irix6.5.5 – 6.5.5
- sgi / irix6.5.6 – 6.5.6
- sgi / irix6.5.7 – 6.5.7
- sgi / irix6.5.8 – 6.5.8
- sgi / irix6.5.9 – 6.5.9
- sgi / irix6.5.10 – 6.5.10
- sun / linux5.0.7 – 5.0.7
- sun / solaris8.0 – 8.0
- sun / solaris9.0 – 9.0
- sun / solaris9.0 – 9.0
- sun / sunos5.8 – 5.8
References
- MISChttp://www.redhat.com/support/errata/RHSA-2003-256.html
- MAILING_LISThttp://marc.info/?l=bugtraq&m=104040175522502&w=2
- MISChttp://use.perl.org/articles/02/10/06/1118222.shtml?tid=5
- MISCftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.1/SCOSA-2004.1.txt
- MISChttp://www.redhat.com/support/errata/RHSA-2003-257.html
- MAILING_LISThttp://marc.info/?l=bugtraq&m=104033126305252&w=2
- VENDOR_ADVISORYftp://patches.sgi.com/support/free/security/advisories/20030606-01-A
- MAILING_LISThttp://marc.info/?l=bugtraq&m=104005919814869&w=2
- MISCftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2004-007.0.txt
- MISChttp://www.iss.net/security_center/static/10574.php
- MISChttp://www.osvdb.org/3814
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1160
- MISChttp://www.osvdb.org/2183
- VENDOR_ADVISORYhttp://www.debian.org/security/2002/dsa-208
- MISChttp://www.securityfocus.com/bid/6111
- MISChttp://archives.neohapsis.com/archives/vulnwatch/2002-q4/0061.html
- MISChttp://bugs6.perl.org/rt2/Ticket/Display.html?id=17744