CVE-2016-2381
published 2016-04-08CVE-2016-2381: Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
9.01%
94.7th percentile
Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | perl | < perl 5.22.1-8 (bookworm) | perl 5.22.1-8 (bookworm) |
| opensuse | opensuse | — | — |
| oracle | communications_billing_and_revenue_management | — | — |
| oracle | configuration_manager | < 12.1.2.0.4 | 12.1.2.0.4 |
| oracle | configuration_manager | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | enterprise_manager_base_platform | — | — |
| oracle | enterprise_manager_base_platform | — | — |
| oracle | solaris | — | — |
| oracle | timesten_in-memory_database | < 18.1.2.1.0 | 18.1.2.1.0 |
| perl | perl | < 5.23.9 | 5.23.9 |
| perl | perl | >= 0 < 5.22.1-8 | 5.22.1-8 |
| perl | perl | >= 0 < 5.22.1-8 | 5.22.1-8 |
| perl | perl | >= 0 < 5.22.1-8 | 5.22.1-8 |
| perl | perl | >= 0 < 5.22.1-8 | 5.22.1-8 |
| perl | perl | >= 0 < 5.18.2-2ubuntu1.1 | 5.18.2-2ubuntu1.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Perl vulnerabilities
vendor_ubuntu·2016-03-02·CVSS 7.5
CVE-2013-7422 [HIGH] Perl vulnerabilities
Title: Perl vulnerabilities
Summary: Several security issues were fixed in Perl.
It was discovered that Perl incorrectly handled certain regular expressions
with an invalid backreference. An attacker could use this issue to cause
Perl to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2013-7422)
Markus Vervier discovered that Perl incorrectly handled nesting in the
Data::Dumper module. An attacker could use this issue to cause Perl to
consume memory and crash, resulting in a denial of service. (CVE-2014-4330)
Stephane Chazelas discovered that Perl incorrectly handled duplicate
environment variables. An attacker could possibly use this issue to bypass
the taint protection mechanism. (CVE-2016-2381)
Instructions: In general, a standard system update wil
Red Hat
perl: ambiguous environment variables handling
vendor_redhat·2016-03-01·CVSS 7.5
CVE-2016-2381 [HIGH] CWE-20 perl: ambiguous environment variables handling
perl: ambiguous environment variables handling
Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.
Package: perl (Red Hat Directory Server 8) - Will not fix
Package: perl (Red Hat Enterprise Linux 5) - Will not fix
Package: perl (Red Hat Enterprise Linux 6) - Will not fix
Package: perl (Red Hat Enterprise Linux 7) - Will not fix
Package: perl516-perl (Red Hat Software Collections) - Will not fix
Package: rh-perl520-perl (Red Hat Software Collections) - Will not fix
Debian
CVE-2016-2381: perl - Perl might allow context-dependent attackers to bypass the taint protection mech...
vendor_debian·2016·CVSS 7.5
CVE-2016-2381 [HIGH] CVE-2016-2381: perl - Perl might allow context-dependent attackers to bypass the taint protection mech...
Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.
Scope: local
bookworm: resolved (fixed in 5.22.1-8)
bullseye: resolved (fixed in 5.22.1-8)
forky: resolved (fixed in 5.22.1-8)
sid: resolved (fixed in 5.22.1-8)
trixie: resolved (fixed in 5.22.1-8)
GHSA
GHSA-mmf9-wh8f-2qv3: Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp
ghsa_unreviewed·2022-05-13
CVE-2016-2381 [HIGH] CWE-20 GHSA-mmf9-wh8f-2qv3: Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp
Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.
OSV
CVE-2016-2381: Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp
osv·2016-04-08·CVSS 7.5
CVE-2016-2381 [HIGH] CVE-2016-2381: Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp
Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.
OSV
perl vulnerabilities
osv·2016-03-02·CVSS 7.5
CVE-2013-7422 [HIGH] perl vulnerabilities
perl vulnerabilities
It was discovered that Perl incorrectly handled certain regular expressions
with an invalid backreference. An attacker could use this issue to cause
Perl to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2013-7422)
Markus Vervier discovered that Perl incorrectly handled nesting in the
Data::Dumper module. An attacker could use this issue to cause Perl to
consume memory and crash, resulting in a denial of service. (CVE-2014-4330)
Stephane Chazelas discovered that Perl incorrectly handled duplicate
environment variables. An attacker could possibly use this issue to bypass
the taint protection mechanism. (CVE-2016-2381)
Suricata
ET EXPLOIT HP Smart Storage Administrator Remote Command Injection
suricata·2017-03-15
CVE-2016-8523 ET EXPLOIT HP Smart Storage Administrator Remote Command Injection
ET EXPLOIT HP Smart Storage Administrator Remote Command Injection
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 2381 (msg:"ET EXPLOIT HP Smart Storage Administrator Remote Command Injection"; flow:established,to_server; content:"echo -n|20|"; pcre:"/^\s*(?:f0VMR|9FTE|\/RUxG)/R"; reference:cve,2016-8523; classtype:attempted-user; sid:2024063; rev:3; metadata:affected_product HP_Smart_Storage_Administrator, attack_target Server, created_at 2017_03_15, cve CVE_2016_8523, deployment Datacenter, performance_impact Low, confidence High, signature_severity Critical, updated_at 2024_03_07, mitre_tactic_id TA0008, mitre_tactic_name Lateral_Movement, mitre_technique_id T1210, mitre_technique_name Exploitation_Of_Remote_Services;)
No public exploits indexed.
Bugzilla
CVE-2016-2381 perl: ambiguous environment variables handling [fedora-all]
bugzilla·2016-03-02·CVSS 7.5
CVE-2016-2381 [HIGH] CVE-2016-2381 perl: ambiguous environment variables handling [fedora-all]
CVE-2016-2381 perl: ambiguous environment variables handling [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedo
Bugzilla
CVE-2016-2381 perl: ambiguous environment variables handling
bugzilla·2016-02-17·CVSS 7.5
CVE-2016-2381 [HIGH] CVE-2016-2381 perl: ambiguous environment variables handling
CVE-2016-2381 perl: ambiguous environment variables handling
Perl, in all supported versions, has a problem with its handling of ambiguous
environments -- that is, when envp has two entries for a single variable name.
Perl provides a Perl-space hash variable, %ENV, in which environment variables
can be looked up. If variable "X" appears twice in envp, only the last value
would appear in %ENV, but getenv would return the first. Perl's "taint"
security mechanism would be applied to the value in %ENV, but not to other
the rest of the environment. This could result in an ambiguous environment
causing environment variables to be propagated to subprocesses, despite the
protections supposedly offered by taint checking.
With the attached patches, suitable for all supported versions of perl:
a)
http://lists.opensuse.org/opensuse-updates/2016-03/msg00112.htmlhttp://perl5.git.perl.org/perl.git/commitdiff/ae37b791a73a9e78dedb89fb2429d2628cf58076http://www.debian.org/security/2016/dsa-3501http://www.gossamer-threads.com/lists/perl/porters/326387http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.securityfocus.com/bid/83802http://www.ubuntu.com/usn/USN-2916-1https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05240731https://security.gentoo.org/glsa/201701-75https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttp://lists.opensuse.org/opensuse-updates/2016-03/msg00112.htmlhttp://perl5.git.perl.org/perl.git/commitdiff/ae37b791a73a9e78dedb89fb2429d2628cf58076http://www.debian.org/security/2016/dsa-3501http://www.gossamer-threads.com/lists/perl/porters/326387http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.securityfocus.com/bid/83802http://www.ubuntu.com/usn/USN-2916-1https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05240731https://security.gentoo.org/glsa/201701-75https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujul2020.html
2016-04-08
Published