First published: Tue Jun 06 2006(Updated: )
ActiveState ActivePerl 5.8.8.817 for Windows configures the site/lib directory with "Users" group permissions for changing files, which allows local users to gain privileges by creating a malicious sitecustomize.pl file in that directory. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ActiveState ActivePerl | =5.8.8.817 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2856 has been classified as a high-severity vulnerability due to the potential for local users to gain elevated privileges.
To fix CVE-2006-2856, restrict permissions on the site/lib directory to prevent unauthorized modification by non-admin users.
CVE-2006-2856 affects users of ActiveState ActivePerl version 5.8.8.817 for Windows.
Exploiting CVE-2006-2856 allows local users to execute malicious scripts with higher privileges on the affected system.
There is no official patch for CVE-2006-2856, but manually adjusting directory permissions can mitigate the risk.