perl-MDK-Common 1.1.11 and 1.1.24, 1.2.9 through 1.2.14, and possibly other versions, in Mandriva Linux does not properly handle strings when writing them to configuration files, which allows attackers to gain privileges via "special characters" in unspecified vectors.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/34089 | Patch |
http://www.vupen.com/english/advisories/2009/0688 | Vendor Advisory |
http://www.mandriva.com/security/advisories?name=MDVSA-2009:072 | Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/49220 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2009-03-16 10:30
Updated : 2017-08-16 18:30
NVD link : CVE-2009-0912
Mitre link : CVE-2009-0912
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
mandriva
- linux_corporate_server
- multi_network_firewall
- linux