Vulnerability Description
The PlRPC module, possibly 0.2020 and earlier, for Perl uses the Storable module, which allows remote attackers to execute arbitrary code via a crafted request, which is not properly handled when it is deserialized.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Malcolm Nooning | Pirpc | <= 0.2020 |
Related Weaknesses (CWE)
References
- http://seclists.org/oss-sec/2014/q1/56
- http://seclists.org/oss-sec/2014/q1/62
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=734789
- https://bugzilla.redhat.com/show_bug.cgi?id=1030572
- https://bugzilla.redhat.com/show_bug.cgi?id=1051108
- https://rt.cpan.org/Public/Bug/Display.html?id=90474Patch
- http://seclists.org/oss-sec/2014/q1/56
- http://seclists.org/oss-sec/2014/q1/62
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=734789
- https://bugzilla.redhat.com/show_bug.cgi?id=1030572
- https://bugzilla.redhat.com/show_bug.cgi?id=1051108
- https://rt.cpan.org/Public/Bug/Display.html?id=90474Patch
FAQ
What is CVE-2013-7284?
CVE-2013-7284 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The PlRPC module, possibly 0.2020 and earlier, for Perl uses the Storable module, which allows remote attackers to execute arbitrary code via a crafted request, which is not properly handled when it i...
How severe is CVE-2013-7284?
CVE-2013-7284 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-7284?
Check the references section above for vendor advisories and patch information. Affected products include: Malcolm Nooning Pirpc.