|
1 |
| -# created by util/generate at Thu Aug 22 02:08:50 2024 |
2 |
| -# cpan-security-advisory +cf7c1af0eac1915d64b4d4aded75ea7e2ab9525c |
| 1 | +# created by util/generate at Fri Aug 23 11:58:01 2024 |
| 2 | +# cpan-security-advisory +7269468a4aeb9736a5aa0b183d428b243e682572 |
3 | 3 | #
|
4 | 4 | package CPAN::Audit::DB;
|
5 | 5 |
|
6 | 6 | use strict;
|
7 | 7 | use warnings;
|
8 | 8 |
|
9 |
| -our $VERSION = '20240822.001'; |
| 9 | +our $VERSION = '20240823.001'; |
10 | 10 |
|
11 | 11 | sub db {
|
12 | 12 | {
|
@@ -19423,6 +19423,10 @@ sub db {
|
19423 | 19423 | {
|
19424 | 19424 | 'date' => '2024-08-20T11:29:56',
|
19425 | 19425 | 'version' => '1.643_01'
|
| 19426 | + }, |
| 19427 | + { |
| 19428 | + 'date' => '2024-08-22T07:09:52', |
| 19429 | + 'version' => '1.643_02' |
19426 | 19430 | }
|
19427 | 19431 | ]
|
19428 | 19432 | },
|
@@ -35445,6 +35449,53 @@ weakness.
|
35445 | 35449 | ],
|
35446 | 35450 | 'reported' => '2022-01-25',
|
35447 | 35451 | 'severity' => 'critical'
|
| 35452 | + }, |
| 35453 | + { |
| 35454 | + 'affected_versions' => '>=7.44,<=12.23', |
| 35455 | + 'cves' => [ |
| 35456 | + 'CVE-2021-22204' |
| 35457 | + ], |
| 35458 | + 'description' => 'Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image |
| 35459 | +', |
| 35460 | + 'distribution' => 'Image-ExifTool', |
| 35461 | + 'fixed_versions' => '>12.23', |
| 35462 | + 'id' => 'CPANSA-Image-ExifTool-2021-22204', |
| 35463 | + 'references' => [ |
| 35464 | + 'https://rt.cpan.org/Public/Bug/Display.html?id=>=7.44,<=12.23', |
| 35465 | + 'http://packetstormsecurity.com/files/162558/ExifTool-DjVu-ANT-Perl-Injection.html', |
| 35466 | + 'http://packetstormsecurity.com/files/164768/GitLab-Unauthenticated-Remote-ExifTool-Command-Injection.html', |
| 35467 | + 'http://packetstormsecurity.com/files/164994/GitLab-13.10.2-Remote-Code-Execution.html', |
| 35468 | + 'http://packetstormsecurity.com/files/167038/ExifTool-12.23-Arbitrary-Code-Execution.html', |
| 35469 | + 'http://www.openwall.com/lists/oss-security/2021/05/09/1', |
| 35470 | + 'http://www.openwall.com/lists/oss-security/2021/05/10/5', |
| 35471 | + 'https://github.com/exiftool/exiftool/commit/cf0f4e7dcd024ca99615bfd1102a841a25dde031#diff-fa0d652d10dbcd246e6b1df16c1e992931d3bb717a7e36157596b76bdadb3800', |
| 35472 | + 'https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22204.json', |
| 35473 | + 'https://hackerone.com/reports/1154542', |
| 35474 | + 'https://lists.debian.org/debian-lts-announce/2021/05/msg00018.html', |
| 35475 | + 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DDKDLJLBTBBR66OOPXSXCG2PQRM5KCZL/', |
| 35476 | + 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F6UOBPU3LSHAPRRJNISNVXZ5DSUIALLV/', |
| 35477 | + 'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U4RF6PJCJ6NQOVJJJF6HN6BORUQVIXY6/', |
| 35478 | + 'https://www.debian.org/security/2021/dsa-4910' |
| 35479 | + ], |
| 35480 | + 'reported' => '2021-04-23', |
| 35481 | + 'severity' => undef |
| 35482 | + }, |
| 35483 | + { |
| 35484 | + 'affected_versions' => '=8.32', |
| 35485 | + 'cves' => [ |
| 35486 | + 'CVE-2018-20211' |
| 35487 | + ], |
| 35488 | + 'description' => 'ExifTool 8.32 allows local users to gain privileges by creating a %TEMP%\\\\par-%username%\\\\cache-exiftool-8.32 folder with a victim\'s username, and then copying a Trojan horse ws32_32.dll file into this new folder, aka DLL Hijacking. NOTE: 8.32 is an obsolete version from 2010 (9.x was released starting in 2012, and 10.x was released starting in 2015). |
| 35489 | +', |
| 35490 | + 'distribution' => 'Image-ExifTool', |
| 35491 | + 'fixed_versions' => '>8', |
| 35492 | + 'id' => 'CPANSA-Image-ExifTool-2018-20211', |
| 35493 | + 'references' => [ |
| 35494 | + 'http://packetstormsecurity.com/files/150892/Exiftool-8.3.2.0-DLL-Hijacking.html', |
| 35495 | + 'http://seclists.org/fulldisclosure/2018/Dec/44' |
| 35496 | + ], |
| 35497 | + 'reported' => '2019-01-02', |
| 35498 | + 'severity' => undef |
35448 | 35499 | }
|
35449 | 35500 | ],
|
35450 | 35501 | 'main_module' => 'Image::ExifTool',
|
|
0 commit comments