Safe.pm contains a flaw that could allow a local or remote attacker execute code outside of Safe.pm's restricted environment called a compartment. If the compartment has been accessed at least once, an attacker could change the the mask of the compartment to access code outside of the compartment.
Classification
Unknown or Incomplete
Technical
The flaw exists in the Safe->reval() code of Safe.pm. To change the mask the attacker would need to modify the @_ variable.
Solution
Upgrade to the latest version of Safe.pm. Check with your vendor's website for OS specific updates or check http://www.cpan.org
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.