The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.
References
Configurations
History
No history.
Information
Published : 2016-01-13 15:59
Updated : 2024-02-04 18:53
NVD link : CVE-2015-8607
Mitre link : CVE-2015-8607
CVE.ORG link : CVE-2015-8607
JSON object : View
Products Affected
debian
- debian_linux
perl
- pathtools
canonical
- ubuntu_linux
CWE
CWE-20
Improper Input Validation