VDB

GCVE-110-MAGEIA-2024-127

GCVE-110-MAGEIA-2024-127
Advisory Published
Vulnetix · Advisory published April 13, 2024
HTTP::Body::Multipart in the HTTP-Body 1.08, 1.17, and earlier module for Perl uses the part of the uploaded file's name after the first "." character as the suffix of a temporary file, which makes it easier for remote attackers to conduct attacks by leveraging subsequent behavior that may assume the suffix is well-formed. (CVE-2013-4407)

Affected Products

VendorProductVersionsPlatforms
Mageiafiretools0.9.72-1.mga9 (unaffected), 0 (affected)
Mageiaperl-HTTP-Body0 (affected), 1.230.0-1.mga9 (unaffected), 0 (affected), 1.230.0-1.mga9 (unaffected)

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›