Debian Perl vulnerabilities
65 known vulnerabilities affecting debian/perl.
Total CVEs
65
CISA KEV
0
Public exploits
9
Exploited in wild
1
Severity breakdown
CRITICAL8HIGH23MEDIUM16LOW18
Vulnerabilities
Page 1 of 4
CVE-2009-1391P2LOWCVSS 6.8ExploitedPoCfixed in libcompress-raw-zlib-perl 2.015-2 (bookworm)2009
CVE-2009-1391 [MEDIUM] CVE-2009-1391: libcompress-raw-zlib-perl - Off-by-one error in the inflate function in Zlib.xs in Compress::Raw::Zlib Perl ...
Off-by-one error in the inflate function in Zlib.xs in Compress::Raw::Zlib Perl module before 2.017, as used in AMaViS, SpamAssassin, and possibly other products, allows context-dependent attackers to cause a denial of service (hang or crash) via a crafted zlib compressed stream that triggers a heap-based buffer overflow, as exploited in the wild b
debian
CVE-2012-6329P2HIGHCVSS 7.5PoCfixed in perl 5.14.2-16 (bookworm)2012
CVE-2012-6329 [HIGH] CVE-2012-6329: perl - The _compile function in Maketext.pm in the Locale::Maketext implementation in P...
The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly handle backslashes and fully qualified method names during compilation of bracket notation, which allows context-dependent attackers to execute arbitrary commands via crafted input to an application that accepts translation strings from users, as demonstrat
debian
CVE-2011-3597P2LOWCVSS 7.5PoCfixed in perl 5.12.4-6 (bookworm)2011
CVE-2011-3597 [HIGH] CVE-2011-3597: perl - Eval injection vulnerability in the Digest module before 1.17 for Perl allows co...
Eval injection vulnerability in the Digest module before 1.17 for Perl allows context-dependent attackers to execute arbitrary commands via the new constructor.
Scope: local
bookworm: resolved (fixed in 5.12.4-6)
bullseye: resolved (fixed in 5.12.4-6)
forky: resolved (fixed in 5.12.4-6)
sid: resolved (fixed in 5.12.4-6)
trixie: resolved (fixed in 5.12.4-6)
debian
CVE-2022-48522P2LOWCVSS 9.8fixed in perl 5.36.0-4 (bookworm)2022
CVE-2022-48522 [CRITICAL] CVE-2022-48522: perl - In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that ...
In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalation.
Scope: local
bookworm: resolved (fixed in 5.36.0-4)
bullseye: resolved
forky: resolved (fixed in 5.36.0-4)
sid: resolved (fixed in 5.36.0-4)
trixie: resolved (fixed in 5.36.0-4)
debian
CVE-2013-1437P3CRITICALCVSS 9.8fixed in libmodule-metadata-perl 1.000015-1 (bookworm)2013
CVE-2013-1437 [CRITICAL] CVE-2013-1437: libmodule-metadata-perl - Eval injection vulnerability in the Module-Metadata module before 1.000015 for P...
Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute arbitrary Perl code via the $Version value.
Scope: local
bookworm: resolved (fixed in 1.000015-1)
bullseye: resolved (fixed in 1.000015-1)
forky: resolved (fixed in 1.000015-1)
sid: resolved (fixed in 1.000015-1)
trixie: resolved (
debian
CVE-2011-1487P3LOWCVSS 5.0PoCfixed in perl 5.10.1-20 (bookworm)2011
CVE-2011-1487 [MEDIUM] CVE-2011-1487: perl - The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11....
The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.
Scope: local
bookworm: resolved (fixed i
debian
CVE-2018-6913P3CRITICALCVSS 9.8fixed in perl 5.26.1-6 (bookworm)2018
CVE-2018-6913 [CRITICAL] CVE-2018-6913: perl - Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows con...
Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbitrary code via a large item count.
Scope: local
bookworm: resolved (fixed in 5.26.1-6)
bullseye: resolved (fixed in 5.26.1-6)
forky: resolved (fixed in 5.26.1-6)
sid: resolved (fixed in 5.26.1-6)
trixie: resolved (fixed in 5.26.1-6)
debian
CVE-2018-18311P3CRITICALCVSS 9.8fixed in perl 5.28.1-1 (bookworm)2018
CVE-2018-18311 [CRITICAL] CVE-2018-18311: perl - Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted ...
Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
Scope: local
bookworm: resolved (fixed in 5.28.1-1)
bullseye: resolved (fixed in 5.28.1-1)
forky: resolved (fixed in 5.28.1-1)
sid: resolved (fixed in 5.28.1-1)
trixie: resolved (fixed in 5.28.1-1)
debian
CVE-2018-18312P3CRITICALCVSS 9.8fixed in perl 5.28.1-1 (bookworm)2018
CVE-2018-18312 [CRITICAL] CVE-2018-18312: perl - Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted ...
Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
Scope: local
bookworm: resolved (fixed in 5.28.1-1)
bullseye: resolved (fixed in 5.28.1-1)
forky: resolved (fixed in 5.28.1-1)
sid: resolved (fixed in 5.28.1-1)
trixie: resolved (fixed in 5.28.1-1)
debian
CVE-2020-10543P3HIGHCVSS 8.2fixed in perl 5.30.3-1 (bookworm)2020
CVE-2020-10543 [HIGH] CVE-2020-10543: perl - Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow becau...
Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.
Scope: local
bookworm: resolved (fixed in 5.30.3-1)
bullseye: resolved (fixed in 5.30.3-1)
forky: resolved (fixed in 5.30.3-1)
sid: resolved (fixed in 5.30.3-1)
trixie: resolved (fixed in 5.30.3-1)
debian
CVE-2018-6797P3CRITICALCVSS 9.8fixed in perl 5.26.1-6 (bookworm)2018
CVE-2018-6797 [CRITICAL] CVE-2018-6797: perl - An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression ...
An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes written.
Scope: local
bookworm: resolved (fixed in 5.26.1-6)
bullseye: resolved (fixed in 5.26.1-6)
forky: resolved (fixed in 5.26.1-6)
sid: resolved (fixed in 5.26.1-6)
trixie: resolved (fixed in 5.26.1-6)
debian
CVE-2018-18314P3CRITICALCVSS 9.8fixed in perl 5.28.0-3 (bookworm)2018
CVE-2018-18314 [CRITICAL] CVE-2018-18314: perl - Perl before 5.26.3 has a buffer overflow via a crafted regular expression that t...
Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
Scope: local
bookworm: resolved (fixed in 5.28.0-3)
bullseye: resolved (fixed in 5.28.0-3)
forky: resolved (fixed in 5.28.0-3)
sid: resolved (fixed in 5.28.0-3)
trixie: resolved (fixed in 5.28.0-3)
debian
CVE-2018-12015P3HIGHCVSS 7.5fixed in perl 5.26.2-6 (bookworm)2018
CVE-2018-12015 [HIGH] CVE-2018-12015: perl - In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypas...
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.
Scope: local
bookworm: resolved (fixed in 5.26.2-6)
bullseye: resolved (fixed in 5.26.2-6)
forky: resolved (fixed in 5.26.2-6)
sid: re
debian
CVE-2026-4176P3LOWCVSS 2.9fixed in perl 5.10.0-21 (bookworm)2026
CVE-2026-4176 [LOW] CVE-2026-4176: perl - Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from ...
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of zlib which has several vulnerabilities, including CVE-2026-27171. The bundle
debian
CVE-2016-2381P3HIGHCVSS 7.5fixed in perl 5.22.1-8 (bookworm)2016
CVE-2016-2381 [HIGH] CVE-2016-2381: perl - Perl might allow context-dependent attackers to bypass the taint protection mech...
Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.
Scope: local
bookworm: resolved (fixed in 5.22.1-8)
bullseye: resolved (fixed in 5.22.1-8)
forky: resolved (fixed in 5.22.1-8)
sid: resolved (fixed in 5.22.1-8)
trixie: resolved (fixed in 5.22.1-8)
debian
CVE-2020-10878P3HIGHCVSS 8.6fixed in perl 5.30.3-1 (bookworm)2020
CVE-2020-10878 [HIGH] CVE-2020-10878: perl - Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regki...
Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection.
Scope: local
bookworm: resolved (fixed in 5.30.3-1)
bullseye: resolved (fixed in 5.30.3-1)
forky: resolved (fixed in 5.30.3-1)
sid: resolved (fixed in
debian
CVE-2018-18313P3CRITICALCVSS 9.1fixed in perl 5.28.0-3 (bookworm)2018
CVE-2018-18313 [CRITICAL] CVE-2018-18313: perl - Perl before 5.26.3 has a buffer over-read via a crafted regular expression that ...
Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory.
Scope: local
bookworm: resolved (fixed in 5.28.0-3)
bullseye: resolved (fixed in 5.28.0-3)
forky: resolved (fixed in 5.28.0-3)
sid: resolved (fixed in 5.28.0-3)
trixie: resolved (fixed in 5.28.0-3)
debian
CVE-2011-0761P4LOWCVSS 5.0PoCfixed in perl 5.12.0-1 (bookworm)2011
CVE-2011-0761 [MEDIUM] CVE-2011-0761: perl - Perl 5.10.x allows context-dependent attackers to cause a denial of service (NUL...
Perl 5.10.x allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) by leveraging an ability to inject arguments into a (1) getpeername, (2) readdir, (3) closedir, (4) getsockname, (5) rewinddir, (6) tell, or (7) telldir function call.
Scope: local
bookworm: resolved (fixed in 5.12.0-1)
bullseye: resolved (fixed
debian
CVE-2010-1447P3HIGHCVSS 8.5fixed in perl 5.12.3-1 (bookworm)2010
CVE-2010-1447 [HIGH] CVE-2010-1447: perl - The Safe (aka Safe.pm) module 2.26, and certain earlier versions, for Perl, as u...
The Safe (aka Safe.pm) module 2.26, and certain earlier versions, for Perl, as used in PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2, allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execut
debian
CVE-2017-12883P3CRITICALCVSS 9.1fixed in perl 5.26.0-8 (bookworm)2017
CVE-2017-12883 [CRITICAL] CVE-2017-12883: perl - Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5....
Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to disclose sensitive information or cause a denial of service (application crash) via a crafted regular expression with an invalid '\N{U+...}' escape.
Scope: local
bookworm: resolved (fixed in 5.26.0-8)
bullseye: resolved (f
debian
1 / 4Next →