https://seclists.org/oss-sec/2025/q2/220: CVE-2011-10007: File::Find::Rule through 0.34 for Perl is vulnerable to Arbitrary Code Execution when `gp()` encounters a crafted file name
Published Jun 6, 2025
·Updated
Affected Software
1 affected component
Perl File::Find::Rule<=0.34
Frequently Asked Questions
1
What is the severity of CVE-2011-10007?
CVE-2011-10007 has been classified as a high severity vulnerability due to the potential for arbitrary code execution.
2
How do I fix CVE-2011-10007?
To fix CVE-2011-10007, upgrade Perl File::Find::Rule to version 0.35 or later, which addresses this vulnerability.
3
What type of attacks can be executed through CVE-2011-10007?
CVE-2011-10007 can be exploited to execute arbitrary code on a system by manipulating file names processed by the affected software.
4
Which versions of Perl File::Find::Rule are affected by CVE-2011-10007?
Versions of Perl File::Find::Rule through 0.34 are affected by CVE-2011-10007 and are vulnerable to this issue.
5
What environments are at risk due to CVE-2011-10007?
Any environment using an affected version of Perl File::Find::Rule that processes untrusted file names is at risk due to CVE-2011-10007.