The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execute arbitrary code via a Trojan horse library under the current working directory.
2016-08-02T14:59:02.943
2025-04-12T10:46:40.837
Deferred
CVSSv3.1: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | perl | perl | < 5.24.1 | Yes |
| Application | perl | perl | < 5.25.3 | Yes |
| Operating System | fedoraproject | fedora | 22 | Yes |
| Operating System | fedoraproject | fedora | 23 | Yes |
| Operating System | fedoraproject | fedora | 24 | Yes |
| Operating System | debian | debian_linux | 8.0 | Yes |
| Operating System | oracle | solaris | 10 | Yes |
| Operating System | oracle | solaris | 11.3 | Yes |
| Operating System | canonical | ubuntu_linux | 12.04 | Yes |
| Operating System | canonical | ubuntu_linux | 14.04 | Yes |
| Operating System | canonical | ubuntu_linux | 16.04 | Yes |
| Operating System | canonical | ubuntu_linux | 17.10 | Yes |