perl-HTTP-Daemon-6.01-24.el8_10
エラータID: AXSA:2026-1220:01
リリース日:
2026/07/08 Wednesday - 20:47
題名:
perl-HTTP-Daemon-6.01-24.el8_10
影響のあるチャネル:
Asianux Server 8 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- Perl の HTTP::Daemon モジュールの send_file() 関数には、
リモートの攻撃者により、任意のコードの実行を可能とする脆弱性
が存在します。(CVE-2026-8450)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2026-8450
HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '> path' and '>> path' open the path for write or append. Untrusted input passed to send_file() can run OS commands at the daemon process UID. The read-pipe form ('cmd |') also leaks subprocess stdout into the HTTP response body. The write-mode forms can create or truncate files at attacker chosen paths.
HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '> path' and '>> path' open the path for write or append. Untrusted input passed to send_file() can run OS commands at the daemon process UID. The read-pipe form ('cmd |') also leaks subprocess stdout into the HTTP response body. The write-mode forms can create or truncate files at attacker chosen paths.
追加情報:
N/A
ダウンロード:
SRPMS
- perl-HTTP-Daemon-6.01-24.el8_10.src.rpm
MD5: 8b63bb3d0ca27414c9e58d60d9512a2b
SHA-256: 311482dc6a46759a1eab9a5f9e97de1ac30cfdaa00b17afab69fbb225730e313
Size: 38.26 kB
Asianux Server 8 for x86_64
- perl-HTTP-Daemon-6.01-24.el8_10.noarch.rpm
MD5: 4cc7a20c219414e4d46f6282630b013b
SHA-256: 260b00e290376002571a71d52ef87602fd25daa5e9a8bd168fd7aa8108e1a4ad
Size: 26.82 kB