CVE-2006-2856Activeperl vulnerability

3 documents3 sources
Severity
4.6MEDIUMNVD
EPSS
0.1%
top 69.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 6
Latest updateMay 1

Description

ActiveState ActivePerl 5.8.8.817 for Windows configures the site/lib directory with "Users" group permissions for changing files, which allows local users to gain privileges by creating a malicious sitecustomize.pl file in that directory. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages1 packages

NVDactivestate/activeperl5.8.8.817

🔴Vulnerability Details

2
GHSA
GHSA-8xc3-rg94-5c3f: ActiveState ActivePerl 52022-05-01
CVEList
CVE-2006-2856: ActiveState ActivePerl 52006-06-06
CVE-2006-2856 — Activestate Activeperl vulnerability | cvebase