CVE Vulnerabilities

CVE-2010-1447

Published: May 19, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
8.5 HIGH
AV:N/AC:M/Au:S/C:C/I:C/A:C
RedHat/V2
6.8 MODERATE
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The Safe (aka Safe.pm) module 2.26, and certain earlier versions, for Perl, as used in PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2, allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving subroutine references and delayed execution.

Affected Software

NameVendorStart VersionEnd Version
PostgresqlPostgresql7.4 (including)7.4 (including)
PostgresqlPostgresql7.4.1 (including)7.4.1 (including)
PostgresqlPostgresql7.4.2 (including)7.4.2 (including)
PostgresqlPostgresql7.4.3 (including)7.4.3 (including)
PostgresqlPostgresql7.4.4 (including)7.4.4 (including)
PostgresqlPostgresql7.4.5 (including)7.4.5 (including)
PostgresqlPostgresql7.4.6 (including)7.4.6 (including)
PostgresqlPostgresql7.4.7 (including)7.4.7 (including)
PostgresqlPostgresql7.4.8 (including)7.4.8 (including)
PostgresqlPostgresql7.4.9 (including)7.4.9 (including)
PostgresqlPostgresql7.4.10 (including)7.4.10 (including)
PostgresqlPostgresql7.4.11 (including)7.4.11 (including)
PostgresqlPostgresql7.4.12 (including)7.4.12 (including)
PostgresqlPostgresql7.4.13 (including)7.4.13 (including)
PostgresqlPostgresql7.4.14 (including)7.4.14 (including)
PostgresqlPostgresql7.4.15 (including)7.4.15 (including)
PostgresqlPostgresql7.4.16 (including)7.4.16 (including)
PostgresqlPostgresql7.4.17 (including)7.4.17 (including)
PostgresqlPostgresql7.4.18 (including)7.4.18 (including)
PostgresqlPostgresql7.4.19 (including)7.4.19 (including)
PostgresqlPostgresql7.4.20 (including)7.4.20 (including)
PostgresqlPostgresql7.4.21 (including)7.4.21 (including)
PostgresqlPostgresql7.4.22 (including)7.4.22 (including)
PostgresqlPostgresql7.4.23 (including)7.4.23 (including)
PostgresqlPostgresql7.4.24 (including)7.4.24 (including)
PostgresqlPostgresql7.4.25 (including)7.4.25 (including)
PostgresqlPostgresql7.4.26 (including)7.4.26 (including)
PostgresqlPostgresql7.4.27 (including)7.4.27 (including)
PostgresqlPostgresql7.4.28 (including)7.4.28 (including)
Red Hat Enterprise Linux 3RedHatperl-2:5.8.0-101.EL3*
Red Hat Enterprise Linux 4RedHatperl-3:5.8.5-53.el4*
Red Hat Enterprise Linux 5RedHatperl-4:5.8.8-32.el5_5.1*
PerlUbuntudapper*
PerlUbuntuhardy*
PerlUbuntujaunty*
PerlUbuntukarmic*
PerlUbuntulucid*
PerlUbuntumaverick*
PerlUbuntunatty*

References