SOAP::Lite 0.50 through 0.52 allows remote attackers to load arbitrary Perl functions by suppling a non-existent function in a script using a SOAP::Lite module, which causes the AUTOLOAD subroutine to trigger.
Link | Tags |
---|---|
http://www.phrack.org/show.php?p=58&a=9 | vendor advisory |
http://use.perl.org/articles/02/04/09/000212.shtml?tid=5 | patch |
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SN-02%3A02.asc | vendor advisory |
http://www.securityfocus.com/bid/4493 | patch vdb entry |
http://www.phrack.com/show.php?p=58&a=9 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/8838 | vdb entry |
http://online.securityfocus.com/archive/1/267051 | mailing list |
http://www.soaplite.com/ | patch |