[ GLSA 202506-10 ] File-Find-Rule: Shell Injection

[email protected] Thu, 12 Jun 2025 09:57:30 -0000
Newsgroups gmane.linux.gentoo.announce
Message-ID <174972225046.7.8414639868381161009@3f85d36892cf>
--===============5734081768312767404==
Content-Type: text/plain; charset="utf-8"

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202506-10
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: Normal
    Title: File-Find-Rule: Shell Injection
     Date: June 12, 2025
     Bugs: #957182
       ID: 202506-10

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

A vulnerability has been discovered in File-Find-Rule, which can lead to
shell injection.

Background
==========

File-Find-Rule is an alternative interface to File::Find.

Affected packages
=================

Package                  Vulnerable    Unaffected
-----------------------  ------------  ------------
dev-perl/File-Find-Rule  < 0.350.0     >= 0.350.0

Description
===========

File-Find-Rule uses the legacy '2-arg' open() call which is susceptible
to shell injection via malicious filenames.

Impact
======

Shell injection may be used to execute arbitrary code using a malicious
filename.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All File-Find-Rule users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=dev-perl/File-Find-Rule-0.350.0"

References
==========

[ 1 ] CVE-2011-10007
      https://nvd.nist.gov/vuln/detail/CVE-2011-10007

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202506-10

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2025 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
--===============5734081768312767404==
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmhKpIoACgkQFMQkOaVy
+9m6sw/+KykuRpmsBril2Y4NRBFProB4lcOVuo317Qo4Dru3HkDYhAtD1PdVPCTW
vDdz7GaD8iNd4nHC7xevAnZVGYs1ZfwMCep2vpcJ1pss0Wl/GBSauAOvs6w/kMbH
+pzbFUluiWji1sXDAbuPFumbFhUeXjog+TBzYZBlANLTErifQvyBLuQCXH2aA2fK
8MCAeT7L1P5wEXk2UVs9uUTjoD7I4+FJrTq1U4emXjGQBK0AFDXrv/iU68pPaOsi
yaQSsP4++Fi9wc8YAYd1lRk22E5Z20TixjJieHnmoKA9Ja6SsQXD+epaprrqJ5rQ
YFFiwnTM9xDBObzhcM3WfxVY8hpc/HkUcVQH+EI2u2Y7MNuCGziLurfDPbuGydzN
rlW03oOaClPP04bQ6cTsazufcGmCRUmmRfQQvv76GO9xfjDSkjTcl257WTieHRkJ
SxbQ7pQN3N4XS9Qko4iKRxTW5KD2L03KnYN4VdvTfgux9sYSB59k2W/q3r2N2T9b
EA4T8PCeGMhhleUNJjZAH4MphWDrV5pJXZr1DyBYi8T31k067Uk4VE9rFZfq3F74
7pTAkhwIFzEx5JY022/ds7QtubFZ9+tlnLcD9ZtlGyLAanhz6BJ4rD8R3PPOXAUy
iLiUdbOzGPZJCeMliRrkOZSs912LM9UiZRq8o0kKTWQIwRcFNCc=
=JtAK
-----END PGP SIGNATURE-----

--===============5734081768312767404==--