Encode.pm, as distributed in Perl through 5.34.0, allows local users to gain privileges via a Trojan horse Encode::ConfigLocal library (in the current working directory) that preempts dynamic module loading. Exploitation requires an unusual configuration, and certain 2021 versions of Encode.pm (3.05 through 3.11). This issue occurs because the || operator evaluates @INC in a scalar context, and thus @INC has only an integer value.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade perlUpgrade perl-encode | Aug 22, 2024 | Aug 11, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Aug 11, 2021 |
| Debian | — | Upgrade perlUpgrade libencode-perl | Jul 30, 2024 | Aug 11, 2021 |
| Gentoo Linux | — | Upgrade dev-lang/perl. | Nov 18, 2024 | Aug 11, 2021 |
| Huawei Euleros 2_0_sp10 | — | — | Oct 11, 2022 | Aug 11, 2021 |
| Oracle Solaris | — | Upgrade runtime/perl-532 to version 5.32.0-11.4.38.0.1.101.2 on Solaris 11.4 | Nov 17, 2021 | Aug 11, 2021 |
| Ubuntu | — | Upgrade perl | Aug 10, 2021 | Aug 9, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub