VDB
GCVE-110-MAGEIA-2024-127
GCVE-110-MAGEIA-2024-127
Advisory Published
HTTP::Body::Multipart in the HTTP-Body 1.08, 1.17, and earlier module
for Perl uses the part of the uploaded file's name after the first "."
character as the suffix of a temporary file, which makes it easier for
remote attackers to conduct attacks by leveraging subsequent behavior
that may assume the suffix is well-formed. (CVE-2013-4407)
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | firetools | 0.9.72-1.mga9 (unaffected), 0 (affected) | — |
| Mageia | perl-HTTP-Body | 0 (affected), 1.230.0-1.mga9 (unaffected), 0 (affected), 1.230.0-1.mga9 (unaffected) | — |
Aliases
References
Updated firetools packages fix bug
advisory
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.