Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Perl PathTools 安全漏洞
Vulnerability Description
Perl是美国程序员拉里-沃尔(Larry Wall)所研发的一种免费且功能强大的跨平台编程语言。PathTools是一套用于系统文件路径的模式匹配工具。 Perl中使用的PathTools 3.62之前版本中的File::Spec模块中的‘canonpath’函数存在安全漏洞,该漏洞源于程序没有正确保存数据的taint属性。攻击者可借助特制的字符串利用该漏洞绕过taint保护机制。
CVSS Information
N/A
Vulnerability Type
N/A