[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3501-1 perl -- perl

ID: oval:org.secpod.oval:def:602400Date: (C)2016-03-03   (M)2023-09-26
Class: PATCHFamily: unix




Stephane Chazelas discovered a bug in the environment handling in Perl. Perl provides a Perl-space hash variable, %ENV, in which environment variables can be looked up. If a variable appears twice in envp, only the last value would appear in %ENV, but getenv would return the first. Perl"s taint security mechanism would be applied to the value in %ENV, but not to the other rest of the environment. This could result in an ambiguous environment causing environment variables to be propagated to subprocesses, despite the protections supposedly offered by taint checking. With this update Perl changes the behavior to match the following: a

Platform:
Debian 8.x
Debian 7.x
Product:
perl
Reference:
DSA-3501-1
CVE-2016-2381
CVE    1
CVE-2016-2381
CPE    3
cpe:/o:debian:debian_linux:7.x
cpe:/o:debian:debian_linux:8.x
cpe:/a:perl:perl

© SecPod Technologies