Back

MEDIUM

perl-libwww-perl: multiple HTTP client download filename vulnerability [OCERT 2010-001]

Published Jul 6, 2010

Description

lwp-download in libwww-perl before 5.835 does not reject downloads to filenames that begin with a . (dot) character, which allows remote servers to create or overwrite files via (1) a 3xx redirect to a URL with a crafted filename or (2) a Content-Disposition header that suggests a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 6, 2010
Updated Aug 7, 2024
Reserved Jun 9, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date May 17, 2010