Skip to content
GitLab
Projects Groups Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in / Register
  • aports aports
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Graph
    • Compare
  • Issues 660
    • Issues 660
    • List
    • Boards
    • Service Desk
    • Milestones
  • Merge requests 324
    • Merge requests 324
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
  • Deployments
    • Deployments
    • Releases
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • alpinealpine
  • aportsaports
  • Issues
  • #2456
Closed
Open
Issue created Dec 03, 2013 by Alexander Belous@belousa

CVE-2013-4407: perl-http-body

HTTP::Body::Multipart in the HTTP-Body 1.08, 1.17, and earlier module for Perl uses the part of the uploaded file’s name after the first “.” character as the suffix of a temporary file, which makes it easier for remote attackers to conduct attacks by leveraging subsequent behavior that may assume the suffix is well-formed.

•CONFIRM:http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=721634
•DEBIAN:DSA-2801
•URL:http://www.debian.org/security/2013/dsa-2801

(from redmine: issue id 2456, created on 2013-12-03, closed on 2013-12-10)

  • Relations:
    • child #2457 (closed)
    • child #2458 (closed)
    • child #2459 (closed)
    • child #2460 (closed)
  • Changesets:
    • Revision 213ebd00 by Natanael Copa on 2013-12-03T15:39:36Z:
main/perl-http-body: upgrade to 1.17 and fix CVE-2013-4407

ref #2456
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information
Assignee
Assign to
Time tracking