Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade perl | Jul 30, 2024 | Feb 7, 2005 |
| Freebsd | — | Upgrade perl-threadedUpgrade perl | Dec 10, 2025 | Feb 2, 2005 |
| Gentoo Linux | — | Upgrade dev-lang/perl. | Oct 30, 2017 | Feb 7, 2005 |
| Oracle Solaris | — | Upgrade consolidation/osnet/osnet-incorporation to version 0.5.11-0.175.2.0.0.42.2 on Solaris 11.2Upgrade runtime/perl-584/extra to version 5.8.4-0.175.1.11.0.3.2 on Solaris 11.1Upgrade runtime/perl-584 to version 5.8.4-0.175.1.11.0.3.2 on Solaris 11.1 | May 29, 2017 | Feb 7, 2005 |
| Suse | — | Upgrade perlUpgrade perl-64bitUpgrade perl-32bitUpgrade perl-x86 | Dec 12, 2013 | Feb 7, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub