4.6
CVSSv2

CVE-2002-1323

Published: 11/12/2002 Updated: 30/10/2018
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Safe.pm 2.0.7 and previous versions, when used in Perl 5.8.0 and previous versions, may allow malicious users to break out of safe compartments in (1) Safe::reval or (2) Safe::rdo using a redefined @_ variable, which is not reset between successive calls.

Vulnerable Product Search on Vulmon Subscribe to Product

safe.pm safe.pm 2.0_7

sun linux 5.0.7

sgi irix 6.5.14

sgi irix 6.5.15

sgi irix 6.5.19

sgi irix 6.5.19f

sgi irix 6.5.22

sgi irix 6.5.3

sgi irix 6.5.10

sgi irix 6.5.11

sgi irix 6.5.17f

sgi irix 6.5.17m

sgi irix 6.5.18

sgi irix 6.5.20f

sgi irix 6.5.20m

sgi irix 6.5.6

sgi irix 6.5.7

safe.pm safe.pm 2.0_6

sgi irix 6.5.12

sgi irix 6.5.13

sgi irix 6.5.18f

sgi irix 6.5.18m

sgi irix 6.5.21f

sgi irix 6.5.21m

sgi irix 6.5.8

sgi irix 6.5.9

sgi irix 6.5

sgi irix 6.5.1

sgi irix 6.5.16

sgi irix 6.5.17

sgi irix 6.5.19m

sgi irix 6.5.2

sgi irix 6.5.4

sgi irix 6.5.5

redhat enterprise linux 2.1

sco unixware 7.1.2

sco unixware 7.1.3

sun solaris 9.0

redhat linux advanced workstation 2.1

sco open unix 8.0

sun sunos 5.8

sun solaris 8.0

Vendor Advisories

A security hole has been discovered in Safepm which is used in all versions of Perl The Safe extension module allows the creation of compartments in which perl code can be evaluated in a new namespace and the code evaluated in the compartment cannot refer to variables outside this namespace However, when a Safe compartment has already been used, ...