CVE-2024-10224

Public on 2024-11-19
Modified on 2024-11-21
Description
Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute arbitrary shell commands by open()ing a "pesky pipe" (such as passing "commands|" as a filename) or by passing arbitrary strings to eval().
Severity
Medium severity
Medium
CVSS v3 Base Score
5.3
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
HAQM Linux 1 perl-Module-ScanDeps No Fix Planned
HAQM Linux 2 - Core perl-Module-ScanDeps 2025-01-21 ALAS2-2025-2738 Fixed
HAQM Linux 2023 perl-Module-ScanDeps 2025-01-06 ALAS2023-2025-797 Fixed

CVSS Scores

Score Type Score Vector
HAQM Linux CVSSv3 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
NVD CVSSv3 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L