Rapid7 Vulnerability & Exploit Database

CESA-2005:105: perl security update

Free InsightVM Trial No credit card necessary
Watch Demo See how it all works
Back to Search

CESA-2005:105: perl security update



Updated Perl packages that fix several security issues are now available for CentOS Linux 3.

Perl is a high-level programming language commonly used for system administration utilities and Web programming. Kevin Finisterre discovered a stack based buffer overflow flaw in sperl, the Perl setuid wrapper. A local user could create a sperl executable script with a carefully created path name, overflowing the buffer and leading to root privilege escalation. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0156 to this issue. Kevin Finisterre discovered a flaw in sperl which can cause debugging information to be logged to arbitrary files. By setting an environment variable, a local user could cause sperl to create, as root, files with arbitrary filenames, or append the debugging information to existing files. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0155 to this issue. Users of Perl are advised to upgrade to these updated packages, which contain backported patches to correct these issues.


  • centos-upgrade-perl
  • centos-upgrade-perl-cgi
  • centos-upgrade-perl-cpan
  • centos-upgrade-perl-db_file
  • centos-upgrade-perl-suidperl

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center