cbcvebase.
CVE-2021-36770
published 2021-08-11

CVE-2021-36770: Encode.pm, as distributed in Perl through 5.34.0, allows local users to gain privileges via a Trojan horse Encode::ConfigLocal library (in the current working…

PriorityP339high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.40%
69.4th percentile
Encode.pm, as distributed in Perl through 5.34.0, allows local users to gain privileges via a Trojan horse Encode::ConfigLocal library (in the current working directory) that preempts dynamic module loading. Exploitation requires an unusual configuration, and certain 2021 versions of Encode.pm (3.05 through 3.11). This issue occurs because the || operator evaluates @INC in a scalar context, and thus @INC has only an integer value.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlibencode-perl< libencode-perl 3.08-2 (bookworm)libencode-perl 3.08-2 (bookworm)
debianperl< libencode-perl 3.08-2 (bookworm)libencode-perl 3.08-2 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
p5-encode_projectp5-encode>= 3.05 < 3.123.12
perlperl>= 0 < 5.32.1-4+deb11u15.32.1-4+deb11u1
perlperl>= 0 < 5.32.1-55.32.1-5
perlperl>= 0 < 5.32.1-55.32.1-5
perlperl>= 0 < 5.32.1-55.32.1-5

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_oracle7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.