Summary: | <dev-perl/File-Find-Rule-0.350.0: Arbitrary Code Execution when grep() encounters a crafted file name | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Sam James <sam> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | IN_PROGRESS --- | ||
Severity: | normal | CC: | perl |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://lists.security.metacpan.org/cve-announce/msg/30183067/ | ||
See Also: |
https://github.com/richardc/perl-file-find-rule/pull/4 https://rt.cpan.org/Public/Bug/Display.html?id=64504 https://bugs.gentoo.org/show_bug.cgi?id=949498 |
||
Whiteboard: | B2 [stable glsa+] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 957183 | ||
Bug Blocks: |
Description
Sam James
![]() ![]() ![]() ![]() The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=be864746e173558ae6ef99397c6e1f1104f4df88 commit be864746e173558ae6ef99397c6e1f1104f4df88 Author: Sam James <sam@gentoo.org> AuthorDate: 2025-06-05 18:20:50 +0000 Commit: Sam James <sam@gentoo.org> CommitDate: 2025-06-05 18:20:50 +0000 dev-perl/File-Find-Rule: add 0.350.0 Bug: https://bugs.gentoo.org/957182 Signed-off-by: Sam James <sam@gentoo.org> dev-perl/File-Find-Rule/File-Find-Rule-0.350.0.ebuild | 19 +++++++++++++++++++ dev-perl/File-Find-Rule/Manifest | 1 + 2 files changed, 20 insertions(+) The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/data/glsa.git/commit/?id=065d592ea76de8de3b2a4a29f35411d4e22ab25c commit 065d592ea76de8de3b2a4a29f35411d4e22ab25c Author: GLSAMaker <glsamaker@gentoo.org> AuthorDate: 2025-06-12 09:56:52 +0000 Commit: Hans de Graaff <graaff@gentoo.org> CommitDate: 2025-06-12 09:57:03 +0000 [ GLSA 202506-10 ] File-Find-Rule: Shell Injection Bug: https://bugs.gentoo.org/957182 Signed-off-by: GLSAMaker <glsamaker@gentoo.org> Signed-off-by: Hans de Graaff <graaff@gentoo.org> glsa-202506-10.xml | 42 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 42 insertions(+) |