The Safe (aka Safe.pm) module before 2.25 for Perl allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving implicitly called methods and implicitly blessed objects, as demonstrated by the (a) DESTROY and (b) AUTOLOAD methods, related to "automagic methods."
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade perlUpgrade perl-suidperl | Dec 1, 2016 | Jun 21, 2010 |
| Debian | — | Upgrade perl | Jul 30, 2024 | Jun 21, 2010 |
| Gentoo Linux | — | Upgrade perl-core/Safe.Upgrade virtual/perl-Safe. | Oct 30, 2017 | Jun 21, 2010 |
| Oracle_linux | — | Upgrade perl-suidperlUpgrade perl | Oct 16, 2024 | Jun 21, 2010 |
| Suse | — | Upgrade perlUpgrade perl-docUpgrade perl-x86Upgrade perl-32bitUpgrade perl-Module-BuildUpgrade perl-baseUpgrade perl-Test-SimpleUpgrade perl-base-32bit | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade perl | Nov 8, 2024 | Jun 21, 2010 |
| Vmsa 2010 0013 | — | Upgrade VMware ESX 3.5 to build number 283373Upgrade VMware ESX 4.0 to build number 294855 | Nov 19, 2010 | Jun 21, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub