Perl 5.x - Digest Module 'Digest->new()' Code Injection

Related Vulnerabilities: CVE-2011-3597  
Publish Date: 02 Oct 2011
Author: anonymous
                							

                source: http://www.securityfocus.com/bid/49911/info

The Digest module for Perl is prone to a vulnerability that will let attackers inject and execute arbitrary Perl code.

Remote attackers can exploit this issue to run arbitrary code in the context of the affected application.

Digest versions prior to 1.17 are affected. 

Digest->new("::MD5lprint 'ownaide\n';exit(1);");