Security Advisories (3)
CVE-2010-2253 (2010-07-06)

lwp-download in libwww-perl before 5.835 does not reject downloads to filenames that begin with a . (dot) character, which allows remote servers to create or overwrite files via (1) a 3xx redirect to a URL with a crafted filename or (2) a Content-Disposition header that suggests a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.

CPANSA-libwww-perl-2017-01 (2017-11-06)

LWP::Protocol::file can open existent file from file:// scheme. However, current version of LWP uses open FILEHANDLE,EXPR and it has ability to execute arbitrary command

CVE-2011-0633 (2011-01-20)

The Net::HTTPS module in libwww-perl (LWP) before 6.00, as used in WWW::Mechanize, LWP::UserAgent, and other products, when running in environments that do not set the If-SSL-Cert-Subject header, does not enable full validation of SSL certificates by default, which allows remote attackers to spoof servers via man-in-the-middle (MITM) attacks involving hostnames that are not properly validated.

NAME

Bundle::LWP - A bundle to install all libwww-perl related modules

SYNOPSIS

perl -MCPAN -e 'install Bundle::LWP'

CONTENTS

URI 1.10 - There are URIs everywhere

Net::FTP 2.00 - If you want ftp://-support

MIME::Base64 - Used in authentication headers

Digest::MD5 - Needed to do Digest authentication

HTML::Tagset - Needed by HTML::Parser

HTML::Parser - Need by HTML::HeadParser

HTML::HeadParser - To get the correct $res->base

LWP - The reason why you need the modules above

DESCRIPTION

This bundle defines all reqreq modules for libwww-perl.

AUTHOR

Gisle Aas <gisle@aas.no>