« List of all CVEs

CVE-2011-1487

Published: 4/11/2011 Last updated: 8/6/2024 Reserved: 3/21/2011

The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Opam packages affected (3)

bap-std conf-perl goblint-cil

Products affected (1)

Product Vendor Version
n/a n/a QCN9001

References (30)