CVE-2013-7284

medium
Published 2014-04-29 · Modified 2026-05-06
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

The PlRPC module, possibly 0.2020 and earlier, for Perl uses the Storable module, which allows remote attackers to execute arbitrary code via a crafted request, which is not properly handled when it is deserialized.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://rt.cpan.org/Public/Bug/Display.html?id=90474

Application impact

VendorProductVersionsFixed
malcolm_nooningpirpc{"endIncluding":"0.2020"}
malcolm_nooningpirpc0.2000
malcolm_nooningpirpc0.2001
malcolm_nooningpirpc0.2002
malcolm_nooningpirpc0.2003
malcolm_nooningpirpc0.2010
malcolm_nooningpirpc0.2011
malcolm_nooningpirpc0.2012
malcolm_nooningpirpc0.2013
malcolm_nooningpirpc0.2014
malcolm_nooningpirpc0.2016
malcolm_nooningpirpc0.2017
malcolm_nooningpirpc0.2018
malcolm_nooningpirpc0.2019

References

CWEs

CWE-94

Verify integrity in audit chain (admin only). AS-IS.