perl-HTTP-Daemon-6.12-6.el9_8.1
エラータID: AXSA:2026-1466:02
Release date:
Thursday, August 6, 2026 - 13:30
Subject:
perl-HTTP-Daemon-6.12-6.el9_8.1
Affected Channels:
MIRACLE LINUX 9 for x86_64
Severity:
High
Description:
The perl-HTTP-Daemon package includes the [HTTP::Daemon](HTTP::Daemon) class, a subclass of IO::Socket::IP. Instances of the [HTTP::Daemon](HTTP::Daemon) class are HTTP/1.1 servers that listen on a socket for incoming requests.
Security Fix(es):
* perl-HTTP-Daemon: [HTTP::Daemon:](HTTP::Daemon:) Arbitrary code execution via OS command injection in send_file() (CVE-2026-8450)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-8450
Solution:
Update packages.
CVEs:
CVE-2026-8450
HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '> path' and '>> path' open the path for write or append. Untrusted input passed to send_file() can run OS commands at the daemon process UID. The read-pipe form ('cmd |') also leaks subprocess stdout into the HTTP response body. The write-mode forms can create or truncate files at attacker chosen paths.
HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '> path' and '>> path' open the path for write or append. Untrusted input passed to send_file() can run OS commands at the daemon process UID. The read-pipe form ('cmd |') also leaks subprocess stdout into the HTTP response body. The write-mode forms can create or truncate files at attacker chosen paths.
Additional Info:
N/A
Download:
SRPMS
- perl-HTTP-Daemon-6.12-6.el9_8.1.src.rpm
MD5: f20b87ca1f44ca654b8cef29e15abd59
SHA-256: e522fb27e65441e19d2e1459a39e28b9ea471f60c26c70c4a34f6f4074b732b0
Size: 62.63 kB
Asianux Server 9 for x86_64
- perl-HTTP-Daemon-6.12-6.el9_8.1.noarch.rpm
MD5: 5d968ba1b138666bf3b760b46a7d7bab
SHA-256: 67b605ba9a47e7b344fb555abc8b537157d3faf6247d081748ec7c3ae487e297
Size: 33.80 kB