MEDIUM · 4.6

CVE-2002-1323

Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of safe compartments in (1) Safe::reval or (2) Safe::rdo using a redefined @_ variable, which is not re...

Vulnerability Description

Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of safe compartments in (1) Safe::reval or (2) Safe::rdo using a redefined @_ variable, which is not reset between successive calls.

CVSS Score

4.6

MEDIUM

AV:L/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Safe.PmSafe.Pm2.0_6
SunLinux5.0.7
SgiIrix6.5
RedhatEnterprise Linux2.1
RedhatLinux Advanced Workstation2.1
ScoOpen Unix8.0
ScoUnixware7.1.2
SunSolaris8.0
SunSunos5.8

References

FAQ

What is CVE-2002-1323?

CVE-2002-1323 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of safe compartments in (1) Safe::reval or (2) Safe::rdo using a redefined @_ variable, which is not re...

How severe is CVE-2002-1323?

CVE-2002-1323 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2002-1323?

Check the references section above for vendor advisories and patch information. Affected products include: Safe.Pm Safe.Pm, Sun Linux, Sgi Irix, Redhat Enterprise Linux, Redhat Linux Advanced Workstation.