Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-48522

Опубликовано: 22 авг. 2023
Источник: debian

Описание

In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
perlfixed5.36.0-4package
perlnot-affectedbullseyepackage
perlnot-affectedbusterpackage

Примечания

  • Might be related to https://bugs.launchpad.net/ubuntu/+source/perl/+bug/2032667

  • which is just a infinite recursion exhausting the stack, with negligible security

  • impact.

  • https://github.com/Perl/perl5/issues/19147

  • Fixed by: https://github.com/Perl/perl5/commit/23cca2d1f4544cb47f1124d98c308ce1f31f09a6 (v5.35.5)

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 2 лет назад

In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalation.

CVSS3: 5.5
redhat
больше 2 лет назад

In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalation.

CVSS3: 9.8
nvd
больше 2 лет назад

In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalation.

CVSS3: 9.8
github
больше 2 лет назад

In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalation.

CVSS3: 9.8
fstec
больше 2 лет назад

Уязвимость функции S_find_uninit_var (sv.c) интерпретатора Perl, позволяющая нарушителю выполнить произвольный код