XSLoader relative path error in Perl in Perl - CVE-2016-6185

 

XSLoader relative path error in Perl in Perl - CVE-2016-6185

Published: July 11, 2016


Vulnerability identifier: #VU114
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6185
CWE-ID: CWE-141
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to obtain elevated privileges on the target system.

The vulnerability exists due to an access control error in Perl. A local user can load arbitrary code from the current working directory by supplying specially crafted data to the XSLoader component.

Successful exploitation of this vulnerability may result in execution of arbitrary code.

Affected software

Perl
PHP
Debian Linux
Fedora
Microsoft Exchange Server
perl

How to mitigate CVE-2016-6185

The vendor has issued a source code fix, available at:

http://perl5.git.perl.org/perl.git/commit/08e3451d7b3b714ad63a27f1b9c2a23ee75d15ee

perl - addressed in versions 5.20.3-332.fc22, 5.22.2-353.fc23, 5.22.2-361.fc24

External References

Related Security Bulletins