CVE-2010-2253

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
06/07/2010
Last modified:
11/04/2025

Description

lwp-download in libwww-perl before 5.835 does not reject downloads to filenames that begin with a . (dot) character, which allows remote servers to create or overwrite files via (1) a 3xx redirect to a URL with a crafted filename or (2) a Content-Disposition header that suggests a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gisle_aas:libwww-perl:0.01:*:*:*:*:*:*:*
cpe:2.3:a:gisle_aas:libwww-perl:0.02:*:*:*:*:*:*:*
cpe:2.3:a:gisle_aas:libwww-perl:0.03:*:*:*:*:*:*:*
cpe:2.3:a:gisle_aas:libwww-perl:0.04:*:*:*:*:*:*:*
cpe:2.3:a:gisle_aas:libwww-perl:5.00:*:*:*:*:*:*:*
cpe:2.3:a:gisle_aas:libwww-perl:5.01:*:*:*:*:*:*:*
cpe:2.3:a:gisle_aas:libwww-perl:5.02:*:*:*:*:*:*:*
cpe:2.3:a:gisle_aas:libwww-perl:5.03:*:*:*:*:*:*:*
cpe:2.3:a:gisle_aas:libwww-perl:5.04:*:*:*:*:*:*:*
cpe:2.3:a:gisle_aas:libwww-perl:5.05:*:*:*:*:*:*:*
cpe:2.3:a:gisle_aas:libwww-perl:5.06:*:*:*:*:*:*:*
cpe:2.3:a:gisle_aas:libwww-perl:5.07:*:*:*:*:*:*:*
cpe:2.3:a:gisle_aas:libwww-perl:5.08:*:*:*:*:*:*:*
cpe:2.3:a:gisle_aas:libwww-perl:5.09:*:*:*:*:*:*:*
cpe:2.3:a:gisle_aas:libwww-perl:5.10:*:*:*:*:*:*:*