CVE-2013-4407
Last modified
CVE-2013-4407 is a vulnerability of currently unknown severity. HTTP::Body::Multipart in the HTTP-Body module for Perl (1.07 through 1.22, before 1.23) uses the part of the uploaded file's name after the first "." character as the suffix of a temporary file, which makes it easier for remote attackers to conduct attacks by leveraging subsequent behavior that may assume the suffix is well-formed.. EPSS estimates a 2.88% chance of exploitation in the next 30 days.
Description
HTTP::Body::Multipart in the HTTP-Body module for Perl (1.07 through 1.22, before 1.23) uses the part of the uploaded file's name after the first "." character as the suffix of a temporary file, which makes it easier for remote attackers to conduct attacks by leveraging subsequent behavior that may assume the suffix is well-formed.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Http-Body Project | Http-Body | <= 1.17 |
| Http-Body Project | Http-Body | 0.01 |
| Http-Body Project | Http-Body | 0.2 |
| Http-Body Project | Http-Body | 0.03 |
| Http-Body Project | Http-Body | 0.4 |
| Http-Body Project | Http-Body | 0.5 |
| Http-Body Project | Http-Body | 0.6 |
| Http-Body Project | Http-Body | 0.7 |
| Http-Body Project | Http-Body | 0.8 |
| Http-Body Project | Http-Body | 0.9 |
| Http-Body Project | Http-Body | 1.00 |
| Http-Body Project | Http-Body | 1.01 |
| Http-Body Project | Http-Body | 1.02 |
| Http-Body Project | Http-Body | 1.03 |
| Http-Body Project | Http-Body | 1.04 |
| Http-Body Project | Http-Body | 1.05 |
| Http-Body Project | Http-Body | 1.06 |
| Http-Body Project | Http-Body | 1.07 |
| Http-Body Project | Http-Body | 1.08 |
| Http-Body Project | Http-Body | 1.09 |
| Http-Body Project | Http-Body | 1.10 |
| Http-Body Project | Http-Body | 1.11 |
| Http-Body Project | Http-Body | 1.12 |
| Http-Body Project | Http-Body | 1.14 |
| Http-Body Project | Http-Body | 1.15 |
| Http-Body Project | Http-Body | 1.16 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-4407?
How severe is CVE-2013-4407?
How do I fix CVE-2013-4407?
Are you affected by CVE-2013-4407?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
