ISOMAN

CVE

CVE-2011-2767

mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the administrator's control of HTTP request processing without also permitting unprivileged users to run Perl code in the context of the user account that runs Apache HTTP Server processes.

Severity
CRITICAL
CVSS
9.8
Published
Modified

Linked Releases

References

  1. http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00063.html
  2. http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00065.html
  3. http://www.securityfocus.com/bid/105195
  4. https://access.redhat.com/errata/RHSA-2018:2737
  5. https://access.redhat.com/errata/RHSA-2018:2825
  6. https://access.redhat.com/errata/RHSA-2018:2826
  7. https://bugs.debian.org/644169
  8. https://lists.apache.org/thread.html/c8ebe8aad147a3ad2e7b0e8b2da45263171ab5d0fc7f8c100feaa94d%40%3Cmodperl-cvs.perl.apache.org%3E
  9. https://lists.debian.org/debian-lts-announce/2018/09/msg00018.html
  10. https://mail-archives.apache.org/mod_mbox/perl-modperl/201110.mbox/raw/%3C20111004084343.GA21290%40ktnx.net%3E
  11. https://usn.ubuntu.com/3825-1/
  12. https://usn.ubuntu.com/3825-2/
  13. http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00063.html
  14. http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00065.html
  15. http://www.securityfocus.com/bid/105195
  16. https://access.redhat.com/errata/RHSA-2018:2737
  17. https://access.redhat.com/errata/RHSA-2018:2825
  18. https://access.redhat.com/errata/RHSA-2018:2826
  19. https://bugs.debian.org/644169
  20. https://lists.apache.org/thread.html/c8ebe8aad147a3ad2e7b0e8b2da45263171ab5d0fc7f8c100feaa94d%40%3Cmodperl-cvs.perl.apache.org%3E