CVE-2013-4407
Published Nov 23, 2013
Last updated 6 months ago
Overview
- Description
- HTTP::Body::Multipart in the HTTP-Body module for Perl (1.07 through 1.22, before 1.23) uses the part of the uploaded file's name after the first "." character as the suffix of a temporary file, which makes it easier for remote attackers to conduct attacks by leveraging subsequent behavior that may assume the suffix is well-formed.
- Source
- secalert@redhat.com
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-noinfo
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:http-body_project:http-body:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "28144E4C-E5E1-4C2E-871C-4DA6BF480D3F", "versionEndIncluding": "1.17" }, { "criteria": "cpe:2.3:a:http-body_project:http-body:0.01:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "086FF56C-5540-4C7B-B4FA-898D9694A221" }, { "criteria": "cpe:2.3:a:http-body_project:http-body:0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7E279C36-F0F7-48D9-818E-A9554D724C93" }, { "criteria": "cpe:2.3:a:http-body_project:http-body:0.03:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "800CA924-E48F-484C-A280-3139535597F3" }, { "criteria": "cpe:2.3:a:http-body_project:http-body:0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E723BE34-7F32-4CF8-B356-5D3158097BB7" }, { "criteria": "cpe:2.3:a:http-body_project:http-body:0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C7AD5F14-FB2A-4E3B-9D18-0BCBFB24FA10" }, { "criteria": "cpe:2.3:a:http-body_project:http-body:0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5D4DD326-1C66-452B-AAE2-BFA237578C2B" }, { "criteria": "cpe:2.3:a:http-body_project:http-body:0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "319023AD-9A20-4210-97F6-A7E4BCC42A74" }, { "criteria": "cpe:2.3:a:http-body_project:http-body:0.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5C33540B-3D28-413C-871C-AC7D19A98DAA" }, { "criteria": "cpe:2.3:a:http-body_project:http-body:0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1505FC6C-83EB-4999-92DB-D3CA15332265" }, { "criteria": "cpe:2.3:a:http-body_project:http-body:1.00:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9AD7F3A4-86ED-46C1-8DDF-049C6399FA53" }, { "criteria": "cpe:2.3:a:http-body_project:http-body:1.01:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D113F676-7AED-4360-B91A-38F40C011009" }, { "criteria": "cpe:2.3:a:http-body_project:http-body:1.02:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0C2371FE-DDFD-47B9-B938-10C11379A869" }, { "criteria": "cpe:2.3:a:http-body_project:http-body:1.03:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1D0A64C0-A6BF-45A4-8C66-BB7AEB5FD387" }, { "criteria": "cpe:2.3:a:http-body_project:http-body:1.04:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DB0DA4BA-AECA-40E0-8043-9E7FD11AC1CA" }, { "criteria": "cpe:2.3:a:http-body_project:http-body:1.05:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "03E2FE36-6761-4668-89A5-89AA4FD4A2A9" }, { "criteria": "cpe:2.3:a:http-body_project:http-body:1.06:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "580827C1-57C3-4936-9D01-E6F81203DC3A" }, { "criteria": "cpe:2.3:a:http-body_project:http-body:1.07:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2D94B321-EB9B-4A20-9791-B9F3EA77FC40" }, { "criteria": "cpe:2.3:a:http-body_project:http-body:1.08:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1660BB88-C4FF-4893-B224-BDD8E6F2903D" }, { "criteria": "cpe:2.3:a:http-body_project:http-body:1.09:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7EE71FDF-EEF5-4A12-A9E5-26C6BB4C503B" }, { "criteria": "cpe:2.3:a:http-body_project:http-body:1.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5B37AFF2-42A5-4907-BCA7-D9AA52B9C232" }, { "criteria": "cpe:2.3:a:http-body_project:http-body:1.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E00D95DB-F47A-49D0-8DAC-AEE45BC3E424" }, { "criteria": "cpe:2.3:a:http-body_project:http-body:1.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2E3FB0FD-DF10-4935-A949-79110330275E" }, { "criteria": "cpe:2.3:a:http-body_project:http-body:1.14:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "82011B9A-ACF3-47EE-9323-8CF8A2286EE5" }, { "criteria": "cpe:2.3:a:http-body_project:http-body:1.15:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2821586B-223D-43BB-90EB-D268A573FE2F" }, { "criteria": "cpe:2.3:a:http-body_project:http-body:1.16:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "998BEBCF-BFA2-46A4-BE38-34EADBE4D964" } ], "operator": "OR" } ] } ]