{"id":"UBUNTU-CVE-2011-10007","details":"File::Find::Rule through 0.34 for Perl is vulnerable to Arbitrary Code Execution when `grep()` encounters a crafted filename. A file handle is opened with the 2 argument form of `open()` allowing an attacker controlled filename to provide the MODE parameter to `open()`, turning the filename into a command to be executed. Example: $ mkdir /tmp/poc; echo \u003e \"/tmp/poc/|id\" $ perl -MFile::Find::Rule \\     -E 'File::Find::Rule-\u003egrep(\"foo\")-\u003ein(\"/tmp/poc\")' uid=1000(user) gid=1000(user) groups=1000(user),100(users)","modified":"2026-02-04T04:07:56.515488Z","published":"2025-06-05T12:15:00Z","related":["USN-7620-1"],"upstream":["CVE-2011-10007"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2011-10007"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2011-10007"},{"type":"REPORT","url":"https://lists.security.metacpan.org/cve-announce/msg/30183067/"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-7620-1"}],"affected":[{"package":{"name":"libfile-find-rule-perl","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/libfile-find-rule-perl@0.34-1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.33-1","0.34-1"],"ecosystem_specific":{"binaries":[{"binary_version":"0.34-1","binary_name":"libfile-find-rule-perl"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2011/UBUNTU-CVE-2011-10007.json"}},{"package":{"name":"libfile-find-rule-perl","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/libfile-find-rule-perl@0.34-1?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.34-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libfile-find-rule-perl","binary_version":"0.34-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2011/UBUNTU-CVE-2011-10007.json"}},{"package":{"name":"libfile-find-rule-perl","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/libfile-find-rule-perl@0.34-1?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.34-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libfile-find-rule-perl","binary_version":"0.34-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2011/UBUNTU-CVE-2011-10007.json"}},{"package":{"name":"libfile-find-rule-perl","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/libfile-find-rule-perl@0.34-1ubuntu0.22.04.1?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.34-1ubuntu0.22.04.1"}]}],"versions":["0.34-1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"libfile-find-rule-perl","binary_version":"0.34-1ubuntu0.22.04.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2011/UBUNTU-CVE-2011-10007.json"}},{"package":{"name":"libfile-find-rule-perl","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/libfile-find-rule-perl@0.34-3ubuntu0.24.04.1?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.34-3ubuntu0.24.04.1"}]}],"versions":["0.34-3"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"libfile-find-rule-perl","binary_version":"0.34-3ubuntu0.24.04.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2011/UBUNTU-CVE-2011-10007.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}