Back

MEDIUM

perl: lc(), uc() routines are laundering tainted data

Published Apr 11, 2011

Description

The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

Affected products

Remediation

Red Hat statement

The Red Hat Security Response Team has rated this issue as having low security impact, and it did not affect the versions of perl as shipped with Red Hat Enterprise Linux 4 and 5. A future update in Red Hat Enterprise Linux 6 may address this flaw.

Metrics

Weaknesses (1)

References (18)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 11, 2011
Updated Aug 6, 2024
Reserved Mar 21, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Mar 30, 2011