CVE-2002-1742 Information

Description

SOAP::Lite 0.50 through 0.52 allows remote attackers to load arbitrary Perl functions by suppling a non-existent function in a script using a SOAP::Lite module which causes the AUTOLOAD subroutine to trigger.

Reference

ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SN-023A02.asc http://online.securityfocus.com/archive/1/267051 http://use.perl.org/articles/02/04/09/000212.shtml?tid=5 http://www.phrack.com/show.php?p=58&a=9 http://www.phrack.org/show.php?p=58&a=9 http://www.securityfocus.com/bid/4493 http://www.soaplite.com/ https://exchange.xforce.ibmcloud.com/vulnerabilities/8838

Share on: