Lucene search

K
ubuntucveUbuntu.comUB:CVE-2010-2253
HistoryJul 06, 2010 - 12:00 a.m.

CVE-2010-2253

2010-07-0600:00:00
ubuntu.com
ubuntu.com
12

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.004

Percentile

73.5%

lwp-download in libwww-perl before 5.835 does not reject downloads to
filenames that begin with a . (dot) character, which allows remote servers
to create or overwrite files via (1) a 3xx redirect to a URL with a crafted
filename or (2) a Content-Disposition header that suggests a crafted
filename, and possibly execute arbitrary code as a consequence of writing
to a dotfile in a home directory.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchlibwww-perl< 5.803-4ubuntu0.1UNKNOWN
ubuntu8.04noarchlibwww-perl< 5.808-1ubuntu0.1UNKNOWN
ubuntu9.04noarchlibwww-perl< 5.820-1ubuntu0.1UNKNOWN
ubuntu9.10noarchlibwww-perl< 5.831-1ubuntu0.1UNKNOWN
ubuntu10.04noarchlibwww-perl< 5.834-1ubuntu0.1UNKNOWN

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.004

Percentile

73.5%