Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <52535F90.4000506@redhat.com>
Date: Tue, 08 Oct 2013 12:27:44 +1100
From: Murray McAllister <mmcallis@...hat.com>
To: oss-security@...ts.openwall.com
CC: cve-assign@...re.org, kseifried@...hat.com
Subject: CVE Request: remote command-injection flaw in HTTP::Body::Multipart
 versions 1.08 and later

Good morning,

A remote command-injection flaw was reported in HTTP::Body::Multipart 
versions 1.08 and later:

- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=721634
- https://rt.cpan.org/Public/Bug/Display.html?id=88342
- https://bugzilla.redhat.com/show_bug.cgi?id=1005669

The affected code is noted in the Debian bug report.

Could a CVE please be assigned if one has not been already?

Thanks,

--
Murray McAllister / Red Hat Security Response Team

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.