5
CVSSv2

CVE-2011-0761

Published: 13/05/2011 Updated: 09/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Perl 5.10.x allows context-dependent malicious users to cause a denial of service (NULL pointer dereference and application crash) by leveraging an ability to inject arguments into a (1) getpeername, (2) readdir, (3) closedir, (4) getsockname, (5) rewinddir, (6) tell, or (7) telldir function call.

Vulnerable Product Search on Vulmon Subscribe to Product

perl perl 5.10.1

perl perl 5.10.0

Vendor Advisories

Debian Bug report logs - #622817 perl: CVE-2011-1487: taint laundering in lc, uc Package: perl; Maintainer for perl is Niko Tyni <ntyni@debianorg>; Source for perl is src:perl (PTS, buildd, popcon) Reported by: Dominic Hargreaves <dom@earthli> Date: Thu, 14 Apr 2011 21:12:02 UTC Severity: important Tags: fixed-ups ...
Debian Bug report logs - #628817 perl NULL pointer dereference Package: perl; Maintainer for perl is Niko Tyni <ntyni@debianorg>; Source for perl is src:perl (PTS, buildd, popcon) Reported by: "Thijs Kinkhorst" <thijs@debianorg> Date: Wed, 1 Jun 2011 15:57:02 UTC Severity: important Tags: security Found in versi ...

Exploits

source: wwwsecurityfocuscom/bid/47766/info Perl is prone to multiple denial-of-service vulnerabilities caused by a NULL-pointer dereference An attacker can exploit these issues to cause an affected application to crash, denying service to legitimate users Perl versions 510x are vulnerable jonathan () blackbox:~/test$ cat poc1pl ...