Back

MEDIUM

perl: NULL pointer dereference via crafted SOCKET, DIRHANDLE or FILEHANDLE value

Published May 13, 2011

Description

Perl 5.10.x allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) by leveraging an ability to inject arguments into a (1) getpeername, (2) readdir, (3) closedir, (4) getsockname, (5) rewinddir, (6) tell, or (7) telldir function call.

Affected products

Remediation

Red Hat statement

Red Hat does not consider this problem to be a security issue. Input passed to these functions should be under the full control of the script author, therefore no trust boundary is crossed.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner certcc
Published May 13, 2011
Updated Aug 6, 2024
Reserved Feb 3, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date May 3, 2011