The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2011-04-11T18:00:00

Updated: 2017-08-16T14:57:01

Reserved: 2011-03-21T00:00:00


Link: CVE-2011-1487

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2011-04-11T18:55:03.773

Modified: 2017-08-17T01:34:14.277


Link: CVE-2011-1487

JSON object: View

cve-icon Redhat Information

No data.

CWE