CVE-2005-4278

4 documents4 sources
Severity
7.2HIGH
EPSS
0.1%
top 77.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 16
Latest updateMay 1

Description

Untrusted search path vulnerability in Perl before 5.8.7-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages1 packages

NVDlarry_wall/perl5.8.6+16

Patches

🔴Vulnerability Details

2
GHSA
GHSA-f2ph-fm4w-vfqw: Untrusted search path vulnerability in Perl before 52022-05-01
CVEList
CVE-2005-4278: Untrusted search path vulnerability in Perl before 52005-12-16

📋Vendor Advisories

1
Debian
CVE-2005-4278: perl - Untrusted search path vulnerability in Perl before 5.8.7-r1 on Gentoo Linux allo...2005
CVE-2005-4278 (HIGH CVSS 7.2) | Untrusted search path vulnerability | cvebase.io