CVE-2016-6185
02.08.2016, 14:59
The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execute arbitrary code via a Trojan horse library under the current working directory.Enginsight
| Vendor | Product | Version |
|---|---|---|
| perl | perl | 5.23.0 ≤ 𝑥 < 5.24.1 |
| perl | perl | 5.25.0 ≤ 𝑥 < 5.25.3 |
| debian | debian_linux | 8.0 |
| oracle | solaris | 11.3 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 17.10 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References