vulnerability

FreeBSD: VID-72bfbb09-5a6a-11e6-a6c3-14dae9d210b8 (CVE-2016-1238): perl -- local arbitrary code execution

Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
Aug 4, 2016
Added
Nov 14, 2016
Modified
Dec 10, 2025

Description

Sawyer X reports: Perl 5.x before 5.22.3-RC2 and 5.24 before 5.24.1-RC2 do not properly remove . (period) characters from the end of the includes directory array, which might allow local users to gain privileges via a Trojan horse module under the current working directory.

Solutions

freebsd-upgrade-package-perl5freebsd-upgrade-package-perl5-18freebsd-upgrade-package-perl5-20freebsd-upgrade-package-perl5-22freebsd-upgrade-package-perl5-24freebsd-upgrade-package-perl5-develfreebsd-upgrade-package-perlfreebsd-upgrade-package-spamassassin
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.