Debian Libencode-Perl vulnerabilities
2 known vulnerabilities affecting debian/libencode-perl.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1LOW1
Vulnerabilities
Page 1 of 1
CVE-2021-36770HIGHCVSS 7.8fixed in libencode-perl 3.08-2 (bookworm)2021
CVE-2021-36770 [HIGH] CVE-2021-36770: libencode-perl - Encode.pm, as distributed in Perl through 5.34.0, allows local users to gain pri...
Encode.pm, as distributed in Perl through 5.34.0, allows local users to gain privileges via a Trojan horse Encode::ConfigLocal library (in the current working directory) that preempts dynamic module loading. Exploitation requires an unusual configuration, and certain 2021 versions of Encode.pm (3.05 through 3.11). This issue occurs because the || operator eva
debian
CVE-2011-2939LOWCVSS 5.1fixed in libencode-perl 2.44-1 (bookworm)2011
CVE-2011-2939 [MEDIUM] CVE-2011-2939: libencode-perl - Off-by-one error in the decode_xs function in Unicode/Unicode.xs in the Encode m...
Off-by-one error in the decode_xs function in Unicode/Unicode.xs in the Encode module before 2.44, as used in Perl before 5.15.6, might allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Unicode string, which triggers a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 2.44-1)
bullseye: resolve
debian