Debian Security Advisory 3441-1

Debian Linux Security Advisory 3441-1 – David Golden of MongoDB discovered that File::Spec::canonpath() in Perl returned untainted strings even if passed tainted input. This defect undermines taint propagation, which is sometimes used to ensure that unvalidated user input does not reach sensitive code.

Leave a Reply