Логотип exploitDog
bind:"BDU:2025-10307" OR bind:"CVE-2025-40909"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2025-10307" OR bind:"CVE-2025-40909"

Количество 15

Количество 15

fstec логотип

BDU:2025-10307

5 месяцев назад

Уязвимость интерпретатора языка программирования Perl, связанная с использованием ненадёжного пути поиска, позволяющая нарушителю выполнить произвольный код или получить несанкционированный доступ к защищаемой информации

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2025-40909

5 месяцев назад

Perl threads have a working directory race condition where file operations may target unintended paths. If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running. This may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit. The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2025-40909

5 месяцев назад

Perl threads have a working directory race condition where file operations may target unintended paths. If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running. This may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit. The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2025-40909

5 месяцев назад

Perl threads have a working directory race condition where file operations may target unintended paths. If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running. This may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit. The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6

CVSS3: 5.9
EPSS: Низкий
msrc логотип

CVE-2025-40909

3 месяца назад

Perl threads have a working directory race condition where file operations may target unintended paths

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2025-40909

5 месяцев назад

Perl threads have a working directory race condition where file operat ...

CVSS3: 5.9
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02051-1

5 месяцев назад

Security update for perl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02027-1

5 месяцев назад

Security update for perl

EPSS: Низкий
redos логотип

ROS-20250821-06

3 месяца назад

Уязвимость perl

CVSS3: 5.9
EPSS: Низкий
rocky логотип

RLSA-2025:12056

около 1 месяца назад

Moderate: perl security update

EPSS: Низкий
rocky логотип

RLSA-2025:11805

3 месяца назад

Moderate: perl security update

EPSS: Низкий
github логотип

GHSA-jpf5-526x-c5hw

5 месяцев назад

Perl threads have a working directory race condition where file operations may target unintended paths. If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running. This may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit. The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6

CVSS3: 5.9
EPSS: Низкий
oracle-oval логотип

ELSA-2025-12056

3 месяца назад

ELSA-2025-12056: perl security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-11805

4 месяца назад

ELSA-2025-11805: perl security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-11804

4 месяца назад

ELSA-2025-11804: perl security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-10307

Уязвимость интерпретатора языка программирования Perl, связанная с использованием ненадёжного пути поиска, позволяющая нарушителю выполнить произвольный код или получить несанкционированный доступ к защищаемой информации

CVSS3: 5.9
0%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2025-40909

Perl threads have a working directory race condition where file operations may target unintended paths. If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running. This may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit. The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6

CVSS3: 5.9
0%
Низкий
5 месяцев назад
redhat логотип
CVE-2025-40909

Perl threads have a working directory race condition where file operations may target unintended paths. If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running. This may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit. The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6

CVSS3: 5.9
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2025-40909

Perl threads have a working directory race condition where file operations may target unintended paths. If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running. This may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit. The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6

CVSS3: 5.9
0%
Низкий
5 месяцев назад
msrc логотип
CVE-2025-40909

Perl threads have a working directory race condition where file operations may target unintended paths

CVSS3: 5.9
0%
Низкий
3 месяца назад
debian логотип
CVE-2025-40909

Perl threads have a working directory race condition where file operat ...

CVSS3: 5.9
0%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02051-1

Security update for perl

0%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02027-1

Security update for perl

0%
Низкий
5 месяцев назад
redos логотип
ROS-20250821-06

Уязвимость perl

CVSS3: 5.9
0%
Низкий
3 месяца назад
rocky логотип
RLSA-2025:12056

Moderate: perl security update

0%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2025:11805

Moderate: perl security update

0%
Низкий
3 месяца назад
github логотип
GHSA-jpf5-526x-c5hw

Perl threads have a working directory race condition where file operations may target unintended paths. If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running. This may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit. The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6

CVSS3: 5.9
0%
Низкий
5 месяцев назад
oracle-oval логотип
ELSA-2025-12056

ELSA-2025-12056: perl security update (MODERATE)

3 месяца назад
oracle-oval логотип
ELSA-2025-11805

ELSA-2025-11805: perl security update (MODERATE)

4 месяца назад
oracle-oval логотип
ELSA-2025-11804

ELSA-2025-11804: perl security update (MODERATE)

4 месяца назад

Уязвимостей на страницу