cbcvebase.
CVE-2016-2381
published 2016-04-08

CVE-2016-2381: Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.

high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.

Affected

25 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianperl< perl 5.22.1-8 (bookworm)perl 5.22.1-8 (bookworm)
opensuseopensuse
oraclecommunications_billing_and_revenue_management
oracleconfiguration_manager< 12.1.2.0.412.1.2.0.4
oracleconfiguration_manager
oracledatabase_server
oracledatabase_server
oracledatabase_server
oracledatabase_server
oracledatabase_server
oracleenterprise_manager_base_platform
oracleenterprise_manager_base_platform
oraclesolaris
oracletimesten_in-memory_database< 18.1.2.1.018.1.2.1.0
perlperl< 5.23.95.23.9
perlperl>= 0 < 5.22.1-85.22.1-8
perlperl>= 0 < 5.22.1-85.22.1-8
perlperl>= 0 < 5.22.1-85.22.1-8
perlperl>= 0 < 5.22.1-85.22.1-8
perlperl>= 0 < 5.18.2-2ubuntu1.15.18.2-2ubuntu1.1

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv7.5HIGH