CVE-2013-4407

HTTP::Body::Multipart in the HTTP-Body 1.08, 1.17, and earlier module for Perl uses the part of the uploaded file's name after the first "." character as the suffix of a temporary file, which makes it easier for remote attackers to conduct attacks by leveraging subsequent behavior that may assume the suffix is well-formed.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:http-body_project:http-body:1.10:*:*:*:*:*:*:*
cpe:2.3:a:http-body_project:http-body:1.09:*:*:*:*:*:*:*
cpe:2.3:a:http-body_project:http-body:1.02:*:*:*:*:*:*:*
cpe:2.3:a:http-body_project:http-body:1.01:*:*:*:*:*:*:*
cpe:2.3:a:http-body_project:http-body:0.03:*:*:*:*:*:*:*
cpe:2.3:a:http-body_project:http-body:0.2:*:*:*:*:*:*:*
cpe:2.3:a:http-body_project:http-body:*:*:*:*:*:*:*:*
cpe:2.3:a:http-body_project:http-body:1.16:*:*:*:*:*:*:*
cpe:2.3:a:http-body_project:http-body:1.08:*:*:*:*:*:*:*
cpe:2.3:a:http-body_project:http-body:1.07:*:*:*:*:*:*:*
cpe:2.3:a:http-body_project:http-body:1.00:*:*:*:*:*:*:*
cpe:2.3:a:http-body_project:http-body:1.05:*:*:*:*:*:*:*
cpe:2.3:a:http-body_project:http-body:0.9:*:*:*:*:*:*:*
cpe:2.3:a:http-body_project:http-body:0.8:*:*:*:*:*:*:*
cpe:2.3:a:http-body_project:http-body:0.5:*:*:*:*:*:*:*
cpe:2.3:a:http-body_project:http-body:1.12:*:*:*:*:*:*:*
cpe:2.3:a:http-body_project:http-body:1.04:*:*:*:*:*:*:*
cpe:2.3:a:http-body_project:http-body:0.4:*:*:*:*:*:*:*
cpe:2.3:a:http-body_project:http-body:0.6:*:*:*:*:*:*:*
cpe:2.3:a:http-body_project:http-body:1.14:*:*:*:*:*:*:*
cpe:2.3:a:http-body_project:http-body:1.15:*:*:*:*:*:*:*
cpe:2.3:a:http-body_project:http-body:0.7:*:*:*:*:*:*:*
cpe:2.3:a:http-body_project:http-body:1.11:*:*:*:*:*:*:*
cpe:2.3:a:http-body_project:http-body:1.06:*:*:*:*:*:*:*
cpe:2.3:a:http-body_project:http-body:0.01:*:*:*:*:*:*:*
cpe:2.3:a:http-body_project:http-body:1.03:*:*:*:*:*:*:*

Information

Published : 2013-11-23 10:55

Updated : 2014-03-31 23:23


NVD link : CVE-2013-4407

Mitre link : CVE-2013-4407


JSON object : View

Advertisement

dedicated server usa

Products Affected

http-body_project

  • http-body