PT-2013-1333 · Twiki+6 · Twiki+6
Vincent Danen
·
Published
2013-01-04
·
Updated
2016-12-08
·
CVE-2012-6329
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Perl versions prior to 5.17.7
TWiki versions prior to 5.1.3
Foswiki versions 1.0.x through 1.0.10 and 1.1.x through 1.1.6
Description
The issue is related to the compile function in Maketext.pm, which does not properly handle backslashes and fully qualified method names during compilation of bracket notation. This allows attackers to execute arbitrary commands via crafted input to an application that accepts translation strings from users. The estimated number of potentially affected devices worldwide is not specified.
Recommendations
For Perl versions prior to 5.17.7, update to version 5.17.7 or later to resolve the issue.
For TWiki versions prior to 5.1.3, update to version 5.1.3 or later.
For Foswiki versions 1.0.x through 1.0.10, update to a version after 1.0.10.
For Foswiki versions 1.1.x through 1.1.6, update to a version after 1.1.6.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Foswiki
Ibm Aix
Perl
Red Hat
Suse
Twiki