The Data::FormValidator module 4.66 and earlier for Perl, when untaint_all_constraints is enabled, does not properly preserve the taint attribute of data, which might allow remote attackers to bypass the taint protection mechanism via form input.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/48167 | vdb entry exploit |
https://rt.cpan.org/Public/Bug/Display.html?id=61792 | exploit |
http://www.openwall.com/lists/oss-security/2011/06/13/5 | mailing list |
http://www.openwall.com/lists/oss-security/2011/06/12/3 | mailing list exploit patch |
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=629511 | patch exploit |
https://bugzilla.redhat.com/show_bug.cgi?id=712694 | patch exploit |
http://www.openwall.com/lists/oss-security/2011/06/13/13 | mailing list exploit patch |
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065416.html | exploit patch vendor advisory |