6.8
CVE-2013-7284
- EPSS 2.17%
- Veröffentlicht 29.04.2014 14:38:49
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
The PlRPC module, possibly 0.2020 and earlier, for Perl uses the Storable module, which allows remote attackers to execute arbitrary code via a crafted request, which is not properly handled when it is deserialized.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Malcolm Nooning ≫ Pirpc SwPlatformperl Version <= 0.2020
Malcolm Nooning ≫ Pirpc Version0.2000 SwPlatformperl
Malcolm Nooning ≫ Pirpc Version0.2001 SwPlatformperl
Malcolm Nooning ≫ Pirpc Version0.2002 SwPlatformperl
Malcolm Nooning ≫ Pirpc Version0.2003 SwPlatformperl
Malcolm Nooning ≫ Pirpc Version0.2010 SwPlatformperl
Malcolm Nooning ≫ Pirpc Version0.2011 SwPlatformperl
Malcolm Nooning ≫ Pirpc Version0.2012 SwPlatformperl
Malcolm Nooning ≫ Pirpc Version0.2013 SwPlatformperl
Malcolm Nooning ≫ Pirpc Version0.2014 SwPlatformperl
Malcolm Nooning ≫ Pirpc Version0.2016 SwPlatformperl
Malcolm Nooning ≫ Pirpc Version0.2017 SwPlatformperl
Malcolm Nooning ≫ Pirpc Version0.2018 SwPlatformperl
Malcolm Nooning ≫ Pirpc Version0.2019 SwPlatformperl
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.17% | 0.836 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-94 Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.