Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute arbitrary shell commands by open()ing a "pesky pipe" (such as passing "commands|" as a filename) or by passing arbitrary strings to eval().
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade perl-Module-ScanDeps | Jul 4, 2025 | Nov 19, 2024 |
| Alpine Linux | — | Upgrade perl-module-scandeps | Aug 8, 2025 | Nov 19, 2024 |
| Amazon Linux Ami 2 | — | Upgrade perl-Module-ScanDeps | Jan 27, 2025 | Nov 19, 2024 |
| Debian | — | Upgrade libmodule-scandeps-perl | Nov 25, 2024 | Nov 19, 2024 |
| Oracle_linux | — | Upgrade perl-Module-ScanDeps | May 26, 2025 | Nov 19, 2024 |
| Redhat_linux | — | No solution existsUpgrade perl-Module-ScanDeps | May 15, 2025 | Nov 19, 2024 |
| Ubuntu | — | Upgrade libmodule-scandeps-perlUpgrade needrestart (Ubuntu Pro)Upgrade needrestartUpgrade libmodule-scandeps-perl (Ubuntu Pro) | Nov 20, 2024 | Nov 19, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub