漏洞信息详情
Perl 代码问题漏洞
漏洞简介
Perl是Perl(PERL)社区的一款通用、解释型、动态的跨平台编程语言。
Perl 5 中存在安全漏洞,该漏洞允许攻击者对Perl5进程的当前目录具有写访问权从而进行命令执行。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://access.redhat.com/security/cve/cve-2021-36770
参考网址
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/6KOZYD7BH2DNIAEZ2ZL4PJ4QUVQI6Y33/
来源:CONFIRM
链接:https://github.com/Perl/perl5/commit/c1a937fef07c061600a0078f4cb53fe9c2136bb9
来源:CONFIRM
链接:https://metacpan.org/dist/Encode/changes
来源:CONFIRM
链接:https://github.com/dankogai/p5-encode/commit/527e482dc70b035d0df4f8c77a00d81f8d775c74
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20210909-0003/
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/5NDGQSGMEZ75FJGBKNYC75OTO7TF7XHB/
来源:MISC
链接:https://security-tracker.debian.org/tracker/CVE-2021-36770
来源:CONFIRM
链接:https://news.cpanel.com/unscheduled-tsr-10-august-2021/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163761/Ubuntu-Security-Notice-USN-5033-1.html
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021081205
来源:access.redhat.com
链接:https://access.redhat.com/security/cve/cve-2021-36770
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2678
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2021-36770
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021092202
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Perl-Encode-pm-code-execution-via-ConfigLocal-36083
受影响实体
暂无
补丁
- Perl 代码问题漏洞的修复措施<!--2021-8-9-->
还没有评论,来说两句吧...