CVE-2011-2767
libapache2-mod-perl2 - security update
9.8
CRITICAL
CVSS 3.1
EPSS 8.9%
Description
mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the administrator's control of HTTP request processing without also permitting unprivileged users to run Perl code in the context of the user account that runs Apache HTTP Server processes.
How to fix CVE-2011-2767
To remediate CVE-2011-2767, upgrade the affected package to a fixed version below.
- —upgrade to 2.0.10-3 or later
- —upgrade to 2.0.9~1624218-2+deb8u3 or later
Is CVE-2011-2767 being exploited?
Moderate — EPSS is 8.9%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 2.0.10-3
- from 0, < 2.0.9~1624218-2+deb8u3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |