CVE-2010-2253: lwp-download in libwww-perl before 5.835 does not reject downloads to filenames that begin with a . (dot) character, which allows remote servers to create or overwrite files and possibly execute arbitrary code. from ian mcwilliam, ok sthen@