Affected Versions:
Perl 5.14.1
Vulnerability description:
Perl is a high-level, general, literal, and dynamic programming language.
Perl's "decode_xs ()" and "File: Glob: bsd_glob ()" functions have a remote code execution vulnerability. Remote attackers can exploit this vulnerability to execute arbitrary code.
1) when processing the GLOB_ALTDIRFUNC flag, errors in the "File: Glob: bsd_glob ()" function can be exploited to illegally access and execute arbitrary code.
2) errors in the "decode_xs ()" function in Encode can cause heap buffer overflow through special input.
<* Reference
Http://cpansearch.perl.org/src/FLORA/perl-5.14.2/pod/perldelta.pod
Http://secunia.com/advisories/46172/
*>
Vendor patch:
Perl
----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.perl.com