CVE-2012-6329
Last modified
CVE-2012-6329 is a vulnerability of currently unknown severity. The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly handle backslashes and fully qualified method names during compilation of bracket notation, which allows context-dependent attackers to execute arbitrary commands via crafted input to an application that accepts translation strings from users, as demonstrated by the TWiki application before 5.1.3, and the Foswiki application 1.0.x through 1.0.10 and 1.1.x through 1.1.6.. EPSS estimates a 61.60% chance of exploitation in the next 30 days.
Description
The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly handle backslashes and fully qualified method names during compilation of bracket notation, which allows context-dependent attackers to execute arbitrary commands via crafted input to an application that accepts translation strings from users, as demonstrated by the TWiki application before 5.1.3, and the Foswiki application 1.0.x through 1.0.10 and 1.1.x through 1.1.6.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Perl | Perl | <= 5.16.2 |
| Perl | Perl | 5.10 |
| Perl | Perl | 5.10.0 |
| Perl | Perl | 5.10.1 |
| Perl | Perl | 5.11.0 |
| Perl | Perl | 5.11.1 |
| Perl | Perl | 5.11.2 |
| Perl | Perl | 5.11.3 |
| Perl | Perl | 5.11.4 |
| Perl | Perl | 5.11.5 |
| Perl | Perl | 5.12.0 |
| Perl | Perl | 5.12.1 |
| Perl | Perl | 5.12.2 |
| Perl | Perl | 5.12.3 |
| Perl | Perl | 5.13.0 |
| Perl | Perl | 5.13.1 |
| Perl | Perl | 5.13.2 |
| Perl | Perl | 5.13.3 |
| Perl | Perl | 5.13.4 |
| Perl | Perl | 5.13.5 |
| Perl | Perl | 5.13.6 |
| Perl | Perl | 5.13.7 |
| Perl | Perl | 5.13.8 |
| Perl | Perl | 5.13.9 |
| Perl | Perl | 5.13.10 |
| Perl | Perl | 5.13.11 |
| Perl | Perl | 5.14.0 |
| Perl | Perl | 5.14.1 |
| Perl | Perl | 5.14.2 |
| Perl | Perl | 5.14.3 |
| Perl | Perl | 5.16.0 |
| Perl | Perl | 5.16.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-6329?
How severe is CVE-2012-6329?
How do I fix CVE-2012-6329?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-6316Multiple cross-site scripting (XSS) vulnerabilities in the T…
- CVE-2012-6324Directory traversal vulnerability in VMware vCenter Server A…
- CVE-2012-6325VMware vCenter Server Appliance (vCSA) 5.0 before Update 2 d…
- CVE-2012-6326VMware vCenter Server 4.1 before Update 3 and 5.0 before Upd…
- CVE-2012-6327Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2012-6328Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2012-6330The localization functionality in TWiki before 5.1.3, and Fo…
- CVE-2012-6333Multiple HVM control operations in Xen 3.4 through 4.2 allow…
- CVE-2012-6334The Track My Mobile feature in the SamsungDive subsystem for…
- CVE-2012-6335The Anti-theft service in AVG AntiVirus for Android allows p…
- CVE-2012-6336The Missing Device feature in Lookout allows physically prox…
- CVE-2012-6337The Track My Mobile feature in the SamsungDive subsystem for…
Are you affected by CVE-2012-6329?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
