CVE-2016-2381: Input Validation
Published Apr 8, 2016
·Updated
Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.
Affected Software
19 affected components
Perl Perl<5.23.9
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Oracle Communications Billing and Revenue Management=7.5
Oracle Configuration Manager<12.1.2.0.4
Oracle Configuration Manager=12.1.2.0.6
Oracle Database Server=11.2.0.4
Oracle Database Server=12.1.0.2
Oracle Database Server=12.2.0.1
Oracle Database Server=18c
Oracle Database Server=19c
Oracle Enterprise Manager Base Platform=13.2.0.0.0
Oracle Enterprise Manager Base Platform=13.3.0.0.0
Oracle TimesTen In-Memory Database<18.1.2.1.0
Oracle Solaris=11.3
openSUSE openSUSE=13.2
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.10
Event History
Apr 8, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2381?
CVE-2016-2381 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2016-2381?
To fix CVE-2016-2381, update your Perl version to 5.24.0 or later, or apply the relevant patches provided by your distribution.
3
Who is affected by CVE-2016-2381?
CVE-2016-2381 affects systems using Perl versions up to 5.23.9 and various distributions like Debian 7.0, Debian 8.0, and Oracle Database.
4
What type of vulnerability is CVE-2016-2381?
CVE-2016-2381 is a security vulnerability that allows context-dependent attackers to bypass the taint protection mechanism in Perl.
5
Are there any known exploits for CVE-2016-2381?
As of now, there are no publicly known exploits specifically targeting CVE-2016-2381.