Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2013-4407
Description:HTTP::Body::Multipart in the HTTP-Body module for Perl (1.07 through 1.22, before 1.23) uses the part of the uploaded file's name after the first "." character as the suffix of a temporary file, which makes it easier for remote attackers to conduct attacks by leveraging subsequent behavior that may assume the suffix is well-formed.
Test IDs: 1.3.6.1.4.1.25623.1.0.850580   1.3.6.1.4.1.25623.1.1.10.2013.0352   1.3.6.1.4.1.25623.1.1.10.2024.0127   1.3.6.1.4.1.25623.1.0.702801  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2013-4407
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=721634
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=721634
http://git.shadowcat.co.uk/gitweb/gitweb.cgi?p=catagits/HTTP-Body.git;a=commit;h=13ac5b23c083bc56e32dd706ca02fca292bd2161
http://git.shadowcat.co.uk/gitweb/gitweb.cgi?p=catagits/HTTP-Body.git;a=commit;h=13ac5b23c083bc56e32dd706ca02fca292bd2161
http://git.shadowcat.co.uk/gitweb/gitweb.cgi?p=catagits/HTTP-Body.git;a=commit;h=cc75c886256f187cda388641931e8dafad6c2346
http://git.shadowcat.co.uk/gitweb/gitweb.cgi?p=catagits/HTTP-Body.git;a=commit;h=cc75c886256f187cda388641931e8dafad6c2346
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00018.html
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00018.html
http://www.debian.org/security/2013/dsa-2801
http://www.debian.org/security/2013/dsa-2801
https://metacpan.org/release/GETTY/HTTP-Body-1.23/
https://metacpan.org/release/GETTY/HTTP-Body-1.23/
https://www.openwall.com/lists/oss-security/2024/04/07/1
https://www.openwall.com/lists/oss-security/2024/04/07/1
http://www.openwall.com/lists/oss-security/2024/04/07/1




© 1998-2025 E-Soft Inc. All rights reserved.