3 ms·
Specifically, he shows that one of the examples in the documentation for the CGI.pm module had an exploitable vulnerability. I think that's overstating things.
by chromatic 9y ago
Specifically, he shows that one of the examples in the documentation for the CGI.pm module had an exploitable vulnerability.
I think that's overstating things. He reported a "vulnerability" in Bugzilla which wasn't a security problem in Bugzilla because Bugzilla uses taint, which didn't do any database injection like he claimed, and which is unrelated to CGI.pm becaues Bugzilla doesn't use CGI.pm:
https://bugzilla.mozilla.org/show_bug.cgi?id=1230932 https://bugzilla.mozilla.org/show_bug.cgi?id=1230932
Furthermore, the examples in his presentation don't actually work, he relies on ignorance of lists and Perl data structures, and the one potentially interesting point he makes about calling functions in list context in hash initializers has been documented well understood as a potential mishap in web applications since 2000:
https://events.ccc.de/congress/2014/Fahrplan/system/attachments/2542/original/the-perl-jam-netanel-rubin-31c3.pdf https://events.ccc.de/congress/2014/Fahrplan/system/attachme...
His presentation may have some value to someone spending their first week with Perl in a web context, but that person would have to wade through a lot of nonsense to get at that value.