perl-PlRPC: pre-auth remote code execution
Published Apr 29, 2014
6.8
MEDIUMCVSS 2.0
EPSS 2.84%
Description
The PlRPC module, possibly 0.2020 and earlier, for Perl uses the Storable module, which allows remote attackers to execute arbitrary code via a crafted request, which is not properly handled when it is deserialized.
Affected products
No data.
- ≤ 0.2020
- 0.2000
- 0.2001
- 0.2002
- 0.2003
- 0.2010
- 0.2011
- 0.2012
- 0.2013
- 0.2014
- 0.2016
- 0.2017
- 0.2018
- 0.2019
No data.
Red Hat Enterprise Linux 7
perl-PlRPC
Will not fix
Red Hat Software Collections
perl516-perl-PlRPC
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | perl-PlRPC | Will not fix | n/a |
| Red Hat Software Collections | perl516-perl-PlRPC | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The Red Hat Security Response Team has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
References (10)
- http://seclists.org/oss-sec/2014/q1/56 mailing-listx_refsource_MLIST
- http://seclists.org/oss-sec/2014/q1/62 mailing-listx_refsource_MLIST
- https://access.redhat.com/security/cve/CVE-2013-7284 Vendor Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=734789 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=1030572 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=1051108 x_refsource_CONFIRMIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-7062 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-7284
- https://rt.cpan.org/Public/Bug/Display.html?id=90474 x_refsource_MISCPatch
- https://www.cve.org/CVERecord?id=CVE-2013-7284
| Link | Providers | Tags |
|---|---|---|
| http://seclists.org/oss-sec/2014/q1/56 | mailing-listx_refsource_MLIST | |
| http://seclists.org/oss-sec/2014/q1/62 | mailing-listx_refsource_MLIST | |
| https://access.redhat.com/security/cve/CVE-2013-7284 | Vendor Advisory | |
| https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=734789 | x_refsource_CONFIRM | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1030572 | x_refsource_CONFIRM | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1051108 | x_refsource_CONFIRMIssue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-7062 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2013-7284 | ||
| https://rt.cpan.org/Public/Bug/Display.html?id=90474 | x_refsource_MISCPatch | |
| https://www.cve.org/CVERecord?id=CVE-2013-7284 |
Change history (0)
No recorded changes yet.