CVE-2016-1238: High severity debian linux vulnerability
(1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6) cpan/Encode/bin/enc2xs, (7) cpan/Encode/bin/encguess, (8) cpan/Encode/bin/piconv, (9) cpan/Encode/bin/ucmlint, (10) cpan/Encode/bin/unidump, (11) cpan/ExtUtils-MakeMaker/bin/instmodsh, (12) cpan/IO-Compress/bin/zipdetails, (13) cpan/JSON-PP/bin/jsonpp, (14) cpan/Test-Harness/bin/prove, (15) dist/ExtUtils-ParseXS/lib/ExtUtils/xsubpp, (16) dist/Module-CoreList/corelist, (17) ext/Pod-Html/bin/pod2html, (18) utils/c2ph.PL, (19) utils/h2ph.PL, (20) utils/h2xs.PL, (21) utils/libnetcfg.PL, (22) utils/perlbug.PL, (23) utils/perldoc.PL, (24) utils/perlivp.PL, and (25) utils/splain.PL in Perl 5.x before 5.22.3-RC2 and 5.24 before 5.24.1-RC2 do not properly remove . (period) characters from the end of the includes directory array, which might allow local users to gain privileges via a Trojan horse module under the current working directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1238?
CVE-2016-1238 is classified as a moderate severity vulnerability.
How do I fix CVE-2016-1238?
To fix CVE-2016-1238, you should update your Perl packages to the latest versions that address this vulnerability.
What products are affected by CVE-2016-1238?
CVE-2016-1238 impacts several versions of Perl and specific distributions such as Debian 8.0 and Fedora versions 23 and 24.
What are the potential impacts of CVE-2016-1238?
The potential impacts of CVE-2016-1238 include denial of service and unauthorized access, depending on the context of the Perl applications in use.
Was CVE-2016-1238 disclosed publicly?
Yes, CVE-2016-1238 was publicly disclosed and is documented in multiple security advisories.