Debian Perl vulnerabilities
65 known vulnerabilities affecting debian/perl.
Total CVEs
65
CISA KEV
0
Public exploits
9
Exploited in wild
1
Severity breakdown
CRITICAL8HIGH23MEDIUM16LOW18
Vulnerabilities
Page 3 of 4
CVE-2017-6512P4MEDIUMCVSS 5.9fixed in perl 5.24.1-3 (bookworm)2017
CVE-2017-6512 [MEDIUM] CVE-2017-6512: perl - Race condition in the rmtree and remove_tree functions in the File-Path module b...
Race condition in the rmtree and remove_tree functions in the File-Path module before 2.13 for Perl allows attackers to set the mode on arbitrary files via vectors involving directory-permission loosening logic.
Scope: local
bookworm: resolved (fixed in 5.24.1-3)
bullseye: resolved (fixed in 5.24.1-3)
forky: resolved (fixed in 5.24.1-3)
sid: resolved (fixed in 5.24.1-3
debian
CVE-2013-1667P4HIGHCVSS 7.5fixed in perl 5.14.2-19 (bookworm)2013
CVE-2013-1667 [HIGH] CVE-2013-1667: perl - The rehash mechanism in Perl 5.8.2 through 5.16.x allows context-dependent attac...
The rehash mechanism in Perl 5.8.2 through 5.16.x allows context-dependent attackers to cause a denial of service (memory consumption and crash) via a crafted hash key.
Scope: local
bookworm: resolved (fixed in 5.14.2-19)
bullseye: resolved (fixed in 5.14.2-19)
forky: resolved (fixed in 5.14.2-19)
sid: resolved (fixed in 5.14.2-19)
trixie: resolved (fixed in 5.14.2-19)
debian
CVE-2007-4829P4MEDIUMCVSS 6.8fixed in perl 5.10.0-19 (bookworm)2007
CVE-2007-4829 [MEDIUM] CVE-2007-4829: perl - Directory traversal vulnerability in the Archive::Tar Perl module 1.36 and earli...
Directory traversal vulnerability in the Archive::Tar Perl module 1.36 and earlier allows user-assisted remote attackers to overwrite arbitrary files via a TAR archive that contains a file whose name is an absolute path or has ".." sequences.
Scope: local
bookworm: resolved (fixed in 5.10.0-19)
bullseye: resolved (fixed in 5.10.0-19)
forky: resolved (fixed in 5.10.0-19
debian
CVE-2025-40909P4MEDIUMCVSS 5.9fixed in perl 5.36.0-7+deb12u3 (bookworm)2025
CVE-2025-40909 [MEDIUM] CVE-2025-40909: perl - Perl threads have a working directory race condition where file operations may t...
Perl threads have a working directory race condition where file operations may target unintended paths. If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running. This may lead to unintended opera
debian
CVE-2012-5526P4MEDIUMCVSS 5.0fixed in libcgi-pm-perl 3.61-2 (bookworm)2012
CVE-2012-5526 [MEDIUM] CVE-2012-5526: libcgi-pm-perl - CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-...
CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject arbitrary headers into responses from applications that use CGI.pm.
Scope: local
bookworm: resolved (fixed in 3.61-2)
bullseye: resolved (fixed in 3.61-2)
forky: resolved (fixed in 3.61-2)
sid: resolved (fixed
debian
CVE-2011-2939P4LOWCVSS 5.1fixed in libencode-perl 2.44-1 (bookworm)2011
CVE-2011-2939 [MEDIUM] CVE-2011-2939: libencode-perl - Off-by-one error in the decode_xs function in Unicode/Unicode.xs in the Encode m...
Off-by-one error in the decode_xs function in Unicode/Unicode.xs in the Encode module before 2.44, as used in Perl before 5.15.6, might allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Unicode string, which triggers a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 2.44-1)
bullseye: resolve
debian
CVE-2002-0703P4HIGHCVSS 7.5fixed in perl 5.8.0-7 (bookworm)2002
CVE-2002-0703 [HIGH] CVE-2002-0703: perl - An interaction between the Perl MD5 module (perl-Digest-MD5) and Perl could prod...
An interaction between the Perl MD5 module (perl-Digest-MD5) and Perl could produce incorrect MD5 checksums for UTF-8 data, which could prevent a system from properly verifying the integrity of the data.
Scope: local
bookworm: resolved (fixed in 5.8.0-7)
bullseye: resolved (fixed in 5.8.0-7)
forky: resolved (fixed in 5.8.0-7)
sid: resolved (fixed in 5.8.0-7)
trixie: reso
debian
CVE-2005-3962P4MEDIUMCVSS 4.6fixed in perl 5.8.7-9 (bookworm)2005
CVE-2005-3962 [MEDIUM] CVE-2005-3962: perl - Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5...
Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5.9.2 and 5.8.6 Perl allows attackers to overwrite arbitrary memory and possibly execute arbitrary code via format string specifiers with large values, which causes an integer wrap and leads to a buffer overflow, as demonstrated using format string vulnerabilities in Perl applications.
Scope
debian
CVE-2010-4410P4MEDIUMCVSS 4.3fixed in libcgi-pm-perl 3.50-1 (bookworm)2010
CVE-2010-4410 [MEDIUM] CVE-2010-4410: libcgi-pm-perl - CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 an...
CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and C
debian
CVE-2010-4411P4MEDIUMCVSS 4.3fixed in libcgi-pm-perl 3.51-1 (bookworm)2010
CVE-2010-4411 [MEDIUM] CVE-2010-4411: libcgi-pm-perl - Unspecified vulnerability in CGI.pm 3.50 and earlier allows remote attackers to ...
Unspecified vulnerability in CGI.pm 3.50 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unknown vectors. NOTE: this issue exists because of an incomplete fix for CVE-2010-2761.
Scope: local
bookworm: resolved (fixed in 3.51-1)
bullseye: resolved (fixed in 3.51-1)
forky: resolved (fixed in 3
debian
CVE-2010-2761P4MEDIUMCVSS 4.3fixed in libcgi-pm-perl 3.50-1 (bookworm)2010
CVE-2010-2761 [MEDIUM] CVE-2010-2761: libcgi-pm-perl - The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::...
The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vuln
debian
CVE-2008-5303P4LOWCVSS 2.6fixed in perl 5.10.0-18 (bookworm)2008
CVE-2008-5303 [LOW] CVE-2008-5303: perl - Race condition in the rmtree function in File::Path 1.08 (lib/File/Path.pm) in P...
Race condition in the rmtree function in File::Path 1.08 (lib/File/Path.pm) in Perl 5.8.8 allows local users to to delete arbitrary files via a symlink attack, a different vulnerability than CVE-2005-0448, CVE-2004-0452, and CVE-2008-2827. NOTE: this is a regression error related to CVE-2005-0448. It is different from CVE-2008-5302 due to affected versions.
Scope: local
b
debian
CVE-2008-5302P4LOWCVSS 2.6fixed in perl 5.10.0-18 (bookworm)2008
CVE-2008-5302 [LOW] CVE-2008-5302: perl - Race condition in the rmtree function in File::Path 1.08 and 2.07 (lib/File/Path...
Race condition in the rmtree function in File::Path 1.08 and 2.07 (lib/File/Path.pm) in Perl 5.8.8 and 5.10.0 allows local users to create arbitrary setuid binaries via a symlink attack, a different vulnerability than CVE-2005-0448, CVE-2004-0452, and CVE-2008-2827. NOTE: this is a regression error related to CVE-2005-0448. It is different from CVE-2008-5303 due to affect
debian
CVE-2008-1927P4MEDIUMCVSS 5.0fixed in perl 5.10.0-1 (bookworm)2008
CVE-2008-1927 [MEDIUM] CVE-2008-1927: perl - Double free vulnerability in Perl 5.8.8 allows context-dependent attackers to ca...
Double free vulnerability in Perl 5.8.8 allows context-dependent attackers to cause a denial of service (memory corruption and crash) via a crafted regular expression containing UTF8 characters. NOTE: this issue might only be present on certain operating systems.
Scope: local
bookworm: resolved (fixed in 5.10.0-1)
bullseye: resolved (fixed in 5.10.0-1)
forky: resolved
debian
CVE-2003-0615P4MEDIUMCVSS 4.3fixed in perl 5.8.0-19 (bookworm)2003
CVE-2003-0615 [MEDIUM] CVE-2003-0615: perl - Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote...
Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote attackers to insert web script via a URL that is fed into the form's action parameter.
Scope: local
bookworm: resolved (fixed in 5.8.0-19)
bullseye: resolved (fixed in 5.8.0-19)
forky: resolved (fixed in 5.8.0-19)
sid: resolved (fixed in 5.8.0-19)
trixie: resolved (fixed in 5.8.0-19)
debian
CVE-2009-3626P4MEDIUMCVSS 5.0fixed in perl 5.10.1-6 (bookworm)2009
CVE-2009-3626 [MEDIUM] CVE-2009-3626: perl - Perl 5.10.1 allows context-dependent attackers to cause a denial of service (app...
Perl 5.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a UTF-8 character with a large, invalid codepoint, which is not properly handled during a regular-expression match.
Scope: local
bookworm: resolved (fixed in 5.10.1-6)
bullseye: resolved (fixed in 5.10.1-6)
forky: resolved (fixed in 5.10.1-6)
sid: resolved (fixed in 5.10
debian
CVE-2003-0900P4MEDIUMCVSS 5.0fixed in perl 5.8.2 (bookworm)2003
CVE-2003-0900 [MEDIUM] CVE-2003-0900: perl - Perl 5.8.1 on Fedora Core does not properly initialize the random number generat...
Perl 5.8.1 on Fedora Core does not properly initialize the random number generator when forking, which makes it easier for attackers to predict random numbers.
Scope: local
bookworm: resolved (fixed in 5.8.2)
bullseye: resolved (fixed in 5.8.2)
forky: resolved (fixed in 5.8.2)
sid: resolved (fixed in 5.8.2)
trixie: resolved (fixed in 5.8.2)
debian
CVE-2011-2728P4LOWCVSS 4.3fixed in perl 5.14.2-1 (bookworm)2011
CVE-2011-2728 [MEDIUM] CVE-2011-2728: perl - The bsd_glob function in the File::Glob module for Perl before 5.14.2 allows con...
The bsd_glob function in the File::Glob module for Perl before 5.14.2 allows context-dependent attackers to cause a denial of service (crash) via a glob expression with the GLOB_ALTDIRFUNC flag, which triggers an uninitialized pointer dereference.
Scope: local
bookworm: resolved (fixed in 5.14.2-1)
bullseye: resolved (fixed in 5.14.2-1)
forky: resolved (fixed in 5.14.2
debian
CVE-2004-0452P4LOWCVSS 2.6fixed in perl 5.8.4-5 (bookworm)2004
CVE-2004-0452 [LOW] CVE-2004-0452: perl - Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and...
Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for the world, which allows local users to delete arbitrary files and directories, and possibly read files and directories, via a symlink attack.
Scope: local
bookworm: resolved (fixed in 5.8.4-5)
bullseye: resolved (fixed in 5.8.4-5)
forky: resolved (fixed i
debian
CVE-2005-0448P4LOWCVSS 2.6fixed in perl 5.8.4-7 (bookworm)2005
CVE-2005-0448 [LOW] CVE-2005-0448: perl - Race condition in the rmtree function in File::Path.pm in Perl before 5.8.4 allo...
Race condition in the rmtree function in File::Path.pm in Perl before 5.8.4 allows local users to create arbitrary setuid binaries in the tree being deleted, a different vulnerability than CVE-2004-0452.
Scope: local
bookworm: resolved (fixed in 5.8.4-7)
bullseye: resolved (fixed in 5.8.4-7)
forky: resolved (fixed in 5.8.4-7)
sid: resolved (fixed in 5.8.4-7)
trixie: resol
debian