The Net::Ping::External extension through 0.15 for Perl does not properly sanitize arguments (e.g., invalid hostnames) containing shell metacharacters before use of backticks in External.pm, allowing for shell command injection and arbitrary command execution if untrusted input is used.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2008-7270 | The Net::Ping::External extension through 0.15 for Perl does not properly sanitize arguments (e.g., invalid hostnames) containing shell metacharacters before use of backticks in External.pm, allowing for shell command injection and arbitrary command execution if untrusted input is used. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-17T00:51:37.142Z
Reserved: 2017-11-07T00:00:00Z
Link: CVE-2008-7319
No data.
Status : Deferred
Published: 2017-11-07T21:29:00.213
Modified: 2025-04-20T01:37:25.860
Link: CVE-2008-7319
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD