Release date:
Updated on:
Affected Systems:
Ubuntu 8.04 LTS
Ubuntu 6.06 LTS
Ubuntu 11.04
Ubuntu 10.04 LTS
Ubuntu 10.10
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2011-1487
Perl is a free and powerful programming language. It is used for Web programming, database processing, XML processing, and system management.
When processing taint input, lc, lcfirst, uc, and ucfirst functions do not correctly apply the taint attribute. Attackers can exploit this vulnerability to bypass certain security conditions. This vulnerability affects only Ubuntu 8.04 LTS, 10.04 LTS, and 10.10.
<* Source: Marc Deslauriers (marc.deslauriers@canonical.com)
Link: http://bugs.debian.org/cgi-bin/bugreport.cgi? Bug = 618489
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Ubuntu
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.ubuntulinux.org/