First published: Sun Jun 12 2011(Updated: )
It was found that perl-Data-FormValidator, a HTML form user input validator, used to treat certain invalid fields as valid, when the untaint_all_constraints directive was used (default for majority of Data-FormValidator routines). A remote attacker could use this flaw to bypass perl Taint mode protection mechanism via specially-crafted input provided to the HTML form. References: [1] <a href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=629511">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=629511</a> [2] <a href="https://rt.cpan.org/Public/Bug/Display.html?id=61792">https://rt.cpan.org/Public/Bug/Display.html?id=61792</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mark Stosberg Data\ | <=4.66 | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Mark Stosberg Data\ | =\-formvalidator | |
Perl Perl |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.