Amazon Linux 2023 Security Advisory: ALAS-2025-797
Advisory Release Date: 2025-01-06 19:21 Pacific
Advisory Updated Date: 2025-01-09 13:05 Pacific
Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute arbitrary shell commands by open()ing a "pesky pipe" (such as passing "commands|" as a filename) or by passing arbitrary strings to eval(). (CVE-2024-10224)
Affected Packages:
perl-Module-ScanDeps
Issue Correction:
Run dnf update perl-Module-ScanDeps --releasever 2023.6.20250107 to update your system.
noarch:
perl-Module-ScanDeps-1.37-1.amzn2023.0.1.noarch
perl-Module-ScanDeps-tests-1.37-1.amzn2023.0.1.noarch
src:
perl-Module-ScanDeps-1.37-1.amzn2023.0.1.src