Vulnerability Description
SOAP::Lite 0.50 through 0.52 allows remote attackers to load arbitrary Perl functions by suppling a non-existent function in a script using a SOAP::Lite module, which causes the AUTOLOAD subroutine to trigger.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Paul Kulchenko | Soap Lite | 0.50 |
References
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SN-02%3A02.ascVendor Advisory
- http://online.securityfocus.com/archive/1/267051
- http://use.perl.org/articles/02/04/09/000212.shtml?tid=5Patch
- http://www.phrack.com/show.php?p=58&a=9
- http://www.phrack.org/show.php?p=58&a=9Vendor Advisory
- http://www.securityfocus.com/bid/4493Patch
- http://www.soaplite.com/Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8838
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SN-02%3A02.ascVendor Advisory
- http://online.securityfocus.com/archive/1/267051
- http://use.perl.org/articles/02/04/09/000212.shtml?tid=5Patch
- http://www.phrack.com/show.php?p=58&a=9
- http://www.phrack.org/show.php?p=58&a=9Vendor Advisory
- http://www.securityfocus.com/bid/4493Patch
- http://www.soaplite.com/Patch
FAQ
What is CVE-2002-1742?
CVE-2002-1742 is a vulnerability with a CVSS score of 5.0 (MEDIUM). SOAP::Lite 0.50 through 0.52 allows remote attackers to load arbitrary Perl functions by suppling a non-existent function in a script using a SOAP::Lite module, which causes the AUTOLOAD subroutine to...
How severe is CVE-2002-1742?
CVE-2002-1742 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-1742?
Check the references section above for vendor advisories and patch information. Affected products include: Paul Kulchenko Soap Lite.