{"id":"OESA-2025-1680","summary":"perl-File-Find-Rule security update","details":"File::Find::Rule is a friendlier interface to File::Find. It allows you to build rules which specify the desired files and directories.\r\n\r\nSecurity Fix(es):\n\nFile::Find::Rule through 0.34 for Perl is vulnerable to Arbitrary Code Execution when `grep()` encounters a crafted filename.\n\nA file handle is opened with the 2 argument form of `open()` allowing an attacker controlled filename to provide the MODE parameter to `open()`, turning the filename into a command to be executed.\n\nExample:\n\n$ mkdir /tmp/poc; echo &gt; &quot;/tmp/poc/|id&quot;\n$ perl -MFile::Find::Rule \\\n    -E &apos;File::Find::Rule-&gt;grep(&quot;foo&quot;)-&gt;in(&quot;/tmp/poc&quot;)&apos;\nuid=1000(user) gid=1000(user) groups=1000(user),100(users)(CVE-2011-10007)","modified":"2026-08-18T01:18:00.644239882Z","published":"2025-06-27T11:08:46Z","upstream":["CVE-2011-10007"],"database_specific":{"severity":"High"},"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1680"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2011-10007"}],"affected":[{"package":{"name":"perl-File-Find-Rule","ecosystem":"openEuler:20.03-LTS-SP4","purl":"pkg:rpm/openEuler/perl-File-Find-Rule&distro=openEuler-20.03-LTS-SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.34-3.oe2003sp4"}]}],"ecosystem_specific":{"src":["perl-File-Find-Rule-0.34-3.oe2003sp4.src.rpm"],"noarch":["perl-File-Find-Rule-0.34-3.oe2003sp4.noarch.rpm","perl-File-Find-Rule-help-0.34-3.oe2003sp4.noarch.rpm"]},"database_specific":{"source":"https://repo.openeuler.org/security/data/osv/OESA-2025-1680.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}