10

CVE-2011-2767

mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the administrator's control of HTTP request processing without also permitting unprivileged users to run Perl code in the context of the user account that runs Apache HTTP Server processes.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Mod Perl Version >= 2.0.0 <= 2.0.10
Debian ≫ Debian Linux Version 8.0
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Version 6.7
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 7.3
Redhat ≫ Enterprise Linux Version 7.4
Redhat ≫ Enterprise Linux Version 7.5
Redhat ≫ Enterprise Linux Version 7.6
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.95% 0.946
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00063.html
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00065.html
http://www.securityfocus.com/bid/105195
Third Party Advisory
VDB Entry
https://access.redhat.com/errata/RHSA-2018:2737
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2825
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2826
Third Party Advisory
https://bugs.debian.org/644169
Third Party Advisory
Mailing List
Issue Tracking
https://lists.apache.org/thread.html/c8ebe8aad147a3ad2e7b0e8b2da45263171ab5d0fc7f8c100feaa94d%40%3Cmodperl-cvs.perl.apache.org%3E
https://lists.debian.org/debian-lts-announce/2018/09/msg00018.html
Third Party Advisory
Mailing List
https://mail-archives.apache.org/mod_mbox/perl-modperl/201110.mbox/raw/%3C20111004084343.GA21290%40ktnx.net%3E
Third Party Advisory
Mailing List
https://usn.ubuntu.com/3825-1/
Third Party Advisory
https://usn.ubuntu.com/3825-2/
Third Party Advisory