Untrusted search path vulnerability in Perl before 5.8.7-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-lang/perl.Upgrade dev-db/qt-unixODBC.Upgrade dev-util/cmake. | Oct 30, 2017 | Dec 16, 2005 |
| Oracle Solaris | — | Upgrade runtime/perl-584 to version 5.8.4-0.175.1.11.0.3.2 on Solaris 11.1Upgrade runtime/perl-584/extra to version 5.8.4-0.175.1.11.0.3.2 on Solaris 11.1Upgrade consolidation/osnet/osnet-incorporation to version 0.5.11-0.175.2.0.0.42.2 on Solaris 11.2 | May 29, 2017 | Dec 16, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub