Opened 4 months ago

Closed 4 months ago

#23327 closed enhancement (fixed)

HTTP-Daemon-6.17 (Perl module)

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: high Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New minor version.

Change History (10)

comment:1 by Douglas R. Reno, 4 months ago

Priority: normal → elevated

This contains a fix for CVE-2026-8450, documented as a remote code execution, arbitrary file write, and response body exfiltration vulnerability. I'm hoping for an email from the CPAN security list about this one too.

comment:2 by Joe Locash, 4 months ago

There's no Makefile.pl in this version. Build.pl wants Module-Build-Tiny, which has other deps...

comment:3 by Bruce Dubbs, 4 months ago

I installed this with 'cpan -i HTTP::Daemon'.

The changes file says:

6.17 2026-05-19 23:11:06Z

  • Fix CVE-2026-8450 (affects 6.15 and earlier): 2-arg open() in send_file() enabled RCE / arbitrary file write / response-body exfiltration when a string argument was derived from attacker- influenced input. send_file() now uses 3-arg open() with an explicit '<' read mode, so the path is always treated as a literal filename and 2-arg open() shell-magic shapes ('| cmd', 'cmd |', '> path', etc.) are no longer interpreted. send_file() now also returns '0E0' (true zero) on a successful zero-byte transfer so callers can distinguish empty file from open failure (undef). See ​https://www.cve.org/CVERecord?id=CVE-2026-8450 for the advisory.

comment:4 by Bruce Dubbs, 4 months ago

Owner: changed from blfs-book to SecurityAdvisory

The change explanation is a little confusing. We currently have version 6.16 in the book so I'm not sure a security advisor is needed or not.

Reassigning to SA for more analysis.

comment:5 by Douglas R. Reno, 4 months ago

After some analysis I can confirm that it the vulnerability does affect 6.16, definitely a typo.

comment:6 by pierre, 4 months ago

Owner: changed from SecurityAdvisory to pierre
Status: new → assigned

Ok, so let's put the dependencies in the book. Those are:

  • HTTP::Message (already in the book, with a lot of dependencies, all in the book)
  • Module::Build::Tiny, which itself depends on:
    • ExtUtils::Config
    • ExtUtils::Helpers
    • ExtUtils::InstallPaths
      Other dependencies of Module::Build::Tiny are in core perl.

So we need to add 4 pages in perl-deps... Taking the ticket for now. Will give back to SecurityAdvisoriy when done

comment:7 by pierre, 4 months ago

Note that HTTP-Daemon has been updated to 6.17 at ff913a4470e2

comment:8 by pierre, 4 months ago

Owner: changed from pierre to SecurityAdvisory
Status: assigned → new

Dependencies added at bf5d147f23

comment:9 by Douglas R. Reno, 4 months ago

Priority: elevated → high

It feels weird promoting this given it's limited usage in *LFS, but the vulnerability is rated as critical on NVD, so to High it goes!

comment:10 by Douglas R. Reno, 4 months ago

Resolution: → fixed
Status: new → closed

SA-13.0-104 issued.

Note: See TracTickets for help on using tickets.