CRITICAL
perl-Module-Metadata: incorrectly documents that it does not execute unsafe code
Published Jan 28, 2020
9.8
CRITICALCVSS 3.1
EPSS 2.94%
Description
Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute arbitrary Perl code via the $Version value.
Affected products
-
- Version before 1.000015StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Perl Toolchain Gang | Module-Metadata | n/a |
|
Configuration 1
- < 1.000015
Configuration 2
OR
- 18
- 19
No data.
Red Hat Enterprise Linux 7
perl-Module-Metadata
Not affected
Red Hat Software Collections
perl516-perl-Module-Metadata
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | perl-Module-Metadata | Not affected | n/a |
| Red Hat Software Collections | perl516-perl-Module-Metadata | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- http://lists.fedoraproject.org/pipermail/package-announce/2013-August/114904.html x_refsource_MISCThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-August/114912.html x_refsource_MISCThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2013-1437 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=996281 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-1475 Advisory
- https://metacpan.org/changes/distribution/Module-Metadata x_refsource_MISCThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-1437
- https://www.cve.org/CVERecord?id=CVE-2013-1437
| Link | Providers | Tags |
|---|---|---|
| http://lists.fedoraproject.org/pipermail/package-announce/2013-August/114904.html | x_refsource_MISCThird Party Advisory | |
| http://lists.fedoraproject.org/pipermail/package-announce/2013-August/114912.html | x_refsource_MISCThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2013-1437 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=996281 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-1475 | Advisory | |
| https://metacpan.org/changes/distribution/Module-Metadata | x_refsource_MISCThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2013-1437 | ||
| https://www.cve.org/CVERecord?id=CVE-2013-1437 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner debian
Published Jan 28, 2020
Updated Aug 6, 2024
Reserved Jan 26, 2013
Link CVE-2013-1437
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2013-1475 Assigner debian
Published Jan 28, 2020
Updated Aug 6, 2024
Exploited since n/a
Link EUVD-2013-1475