Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.
2016-04-08T15:59:05.183
2025-04-12T10:46:40.837
Deferred
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | perl | perl | < 5.23.9 | Yes |
Operating System | debian | debian_linux | 7.0 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |
Application | oracle | communications_billing_and_revenue_management | 7.5 | Yes |
Application | oracle | configuration_manager | < 12.1.2.0.4 | Yes |
Application | oracle | configuration_manager | 12.1.2.0.6 | Yes |
Application | oracle | database_server | 11.2.0.4 | Yes |
Application | oracle | database_server | 12.1.0.2 | Yes |
Application | oracle | database_server | 12.2.0.1 | Yes |
Application | oracle | database_server | 18c | Yes |
Application | oracle | database_server | 19c | Yes |
Application | oracle | enterprise_manager_base_platform | 13.2.0.0.0 | Yes |
Application | oracle | enterprise_manager_base_platform | 13.3.0.0.0 | Yes |
Application | oracle | timesten_in-memory_database | < 18.1.2.1.0 | Yes |
Operating System | oracle | solaris | 11.3 | Yes |
Operating System | opensuse | opensuse | 13.2 | Yes |
Operating System | canonical | ubuntu_linux | 12.04 | Yes |
Operating System | canonical | ubuntu_linux | 14.04 | Yes |
Operating System | canonical | ubuntu_linux | 15.10 | Yes |