CVE-2010-1168

The Safe (aka Safe.pm) module before 2.25 for Perl allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving implicitly called methods and implicitly blessed objects, as demonstrated by the (a) DESTROY and (b) AUTOLOAD methods, related to "automagic methods."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
VendorProductVersion
rafael_garcia-suarezsafe
2.08
rafael_garcia-suarezsafe
2.09
rafael_garcia-suarezsafe
2.11
rafael_garcia-suarezsafe
2.13
rafael_garcia-suarezsafe
2.14
rafael_garcia-suarezsafe
2.15
rafael_garcia-suarezsafe
2.16
rafael_garcia-suarezsafe
2.17
rafael_garcia-suarezsafe
2.18
rafael_garcia-suarezsafe
2.19
rafael_garcia-suarezsafe
2.20
rafael_garcia-suarezsafe
2.21
rafael_garcia-suarezsafe
2.22
rafael_garcia-suarezsafe
2.23
rafael_garcia-suarezsafe
2.24
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
perl
bullseye
5.32.1-4+deb11u3
fixed
bullseye (security)
5.32.1-4+deb11u4
fixed
bookworm
5.36.0-7+deb12u1
fixed
sid
5.40.0-6
fixed
trixie
5.40.0-6
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
perl
natty
Fixed 5.10.1-17ubuntu4.1
released
maverick
Fixed 5.10.1-12ubuntu2.1
released
lucid
Fixed 5.10.1-8ubuntu2.1
released
karmic
ignored
jaunty
ignored
hardy
Fixed 5.8.8-12ubuntu0.5
released
dapper
Fixed 5.8.7-10ubuntu1.3
released
Common Weakness Enumeration
References