CVE-2010-2253
lwp-download in libwww-perl before 5.835 does not reject downloads to filenames that begin with a . (dot) character, which allows remote servers to create or overwrite files via (1) a 3xx redirect to a URL with a crafted filename or (2) a Content-Disposition header that suggests a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.
Published:May 17, 2010
Last Modified:Apr 11, 2025
EPS:Jul 6, 2010
EPSS Score:0.01125
CVSS Score:6.8
Affected Products
Vendor
Product
Action
Vendor
Gisle Aas
Product
Libwww-perl
Gisle Aas
Libwww-perl
Vendor
Search.cpan
Product
Libwww-perl
Search.cpan
Libwww-perl
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
