PT-2016-5149 · Perl Foundation+3 · Perl+3

Published

2016-03-01

·

Updated

2025-01-13

·

CVE-2016-2381

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Perl (affected versions not specified)
Description The issue allows context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1157
CVE-2016-2381
DSA-3501-1
MGASA-2016-0099
RHSA-2026:6206
ROSA-SA-2025-2552
SUSE-SU-2016:2246-1
SUSE-SU-2016:2263-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
USN-2916-1

Affected Products

Alt Linux
Perl
Suse
Ubuntu