Amazon Linux 2023 Security Advisory: ALAS2023-2025-797
Advisory Released Date: 2025-01-09
Advisory Updated Date: 2025-01-09
Severity:
Medium
Issue Overview:
Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute arbitrary shell commands by open()ing a "pesky pipe" (such as passing "commands|" as a filename) or by passing arbitrary strings to eval(). (CVE-2024-10224)
Affected Packages:
perl-Module-ScanDeps
Issue Correction:
Run dnf update perl-Module-ScanDeps --releasever 2023.6.20250107 to update your system.
New Packages:
noarch:
perl-Module-ScanDeps-1.37-1.amzn2023.0.1.noarch
perl-Module-ScanDeps-tests-1.37-1.amzn2023.0.1.noarch
src:
perl-Module-ScanDeps-1.37-1.amzn2023.0.1.src