Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute arbitrary shell commands by open()ing a "pesky pipe" (such as passing "commands|" as a filename) or by passing arbitrary strings to eval().
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-perl-module-scandeps | Jul 4, 2025 | Nov 19, 2024 | |
| Alpine Linux | alpine-linux-upgrade-perl-module-scandeps | Aug 8, 2025 | Nov 19, 2024 | |
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-perl-module-scandeps | Jan 27, 2025 | Nov 19, 2024 | |
| Debian | debian-upgrade-libmodule-scandeps-perl | Nov 25, 2024 | Nov 19, 2024 | |
| Oracle_linux | — | oracle-linux-upgrade-perl-module-scandeps | May 26, 2025 | Nov 19, 2024 |
| Redhat_linux | no-fix-redhat-rpm-packageredhat-upgrade-perl-module-scandeps | May 15, 2025 | Nov 19, 2024 | |
| Ubuntu | ubuntu-pro-upgrade-libmodule-scandeps-perlubuntu-pro-upgrade-needrestartubuntu-upgrade-libmodule-scandeps-perlubuntu-upgrade-needrestart | Nov 20, 2024 | Nov 19, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub