{"id":"CVE-2013-4407","details":"HTTP::Body::Multipart in the HTTP-Body module for Perl (1.07 through 1.22, before 1.23) uses the part of the uploaded file's name after the first \".\" character as the suffix of a temporary file, which makes it easier for remote attackers to conduct attacks by leveraging subsequent behavior that may assume the suffix is well-formed.","modified":"2026-04-16T06:18:36.590574003Z","published":"2013-11-23T18:55:04Z","related":["openSUSE-SU-2024:10492-1"],"references":[{"type":"ADVISORY","url":"http://www.debian.org/security/2013/dsa-2801"},{"type":"WEB","url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=721634"},{"type":"WEB","url":"http://git.shadowcat.co.uk/gitweb/gitweb.cgi?p=catagits/HTTP-Body.git%3Ba=commit%3Bh=13ac5b23c083bc56e32dd706ca02fca292bd2161"},{"type":"WEB","url":"http://git.shadowcat.co.uk/gitweb/gitweb.cgi?p=catagits/HTTP-Body.git%3Ba=commit%3Bh=cc75c886256f187cda388641931e8dafad6c2346"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00018.html"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2024/04/07/1"},{"type":"WEB","url":"https://metacpan.org/release/GETTY/HTTP-Body-1.23/"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2024/04/07/1"}],"schema_version":"1.7.5"}