CVE-2006-2856: Medium severity Activestate ActivePerl vulnerability
ActiveState ActivePerl 5.8.8.817 for Windows configures the site/lib directory with "Users" group permissions for changing files, which allows local users to gain privileges by creating a malicious sitecustomize.pl file in that directory. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2856?
CVE-2006-2856 has been classified as a high-severity vulnerability due to the potential for local users to gain elevated privileges.
How do I fix CVE-2006-2856?
To fix CVE-2006-2856, restrict permissions on the site/lib directory to prevent unauthorized modification by non-admin users.
Who is affected by CVE-2006-2856?
CVE-2006-2856 affects users of ActiveState ActivePerl version 5.8.8.817 for Windows.
What is the risk of exploiting CVE-2006-2856?
Exploiting CVE-2006-2856 allows local users to execute malicious scripts with higher privileges on the affected system.
Is there a patch available for CVE-2006-2856?
There is no official patch for CVE-2006-2856, but manually adjusting directory permissions can mitigate the risk.