← Back

CVE-2016-1238

nvd nist
Published: Aug 2, 2016Modified: May 6, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

(1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6) cpan/Encode/bin/enc2xs, (7) cpan/Encode/bin/encguess, (8) cpan/Encode/bin/piconv, (9) cpan/Encode/bin/ucmlint, (10) cpan/Encode/bin/unidump, (11) cpan/ExtUtils-MakeMaker/bin/instmodsh, (12) cpan/IO-Compress/bin/zipdetails, (13) cpan/JSON-PP/bin/json_pp, (14) cpan/Test-Harness/bin/prove, (15) dist/ExtUtils-ParseXS/lib/ExtUtils/xsubpp, (16) dist/Module-CoreList/corelist, (17) ext/Pod-Html/bin/pod2html, (18) utils/c2ph.PL, (19) utils/h2ph.PL, (20) utils/h2xs.PL, (21) utils/libnetcfg.PL, (22) utils/perlbug.PL, (23) utils/perldoc.PL, (24) utils/perlivp.PL, and (25) utils/splain.PL in Perl 5.x before 5.22.3-RC2 and 5.24 before 5.24.1-RC2 do not properly remove . (period) characters from the end of the includes directory array, which might allow local users to gain privileges via a Trojan horse module under the current working directory.

Affected (253)

Products: Debian: Debian Linux · Fedoraproject: Fedora · Perl: Perl · +2 more
Show all products
1 product
Debian Linux
1 product
Fedora
1 product
Perl
1 product
Leap
1 product
Spamassassin
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
Fedoraproject
Version 23
Version 24
Configuration B
248 vulnerable
Vulnerable SoftwareAffected Versions
Perl
Version 1.0.15
Version 1.0.16
Version 5.000
Version 5.000o
Version 5.001
Version 5.001n
Version 5.002
Version 5.002_01
Version 5.003
Version 5.003_01
Version 5.003_02
Version 5.003_03
Version 5.003_04
Version 5.003_05
Version 5.003_07
Version 5.003_08
Version 5.003_09
Version 5.003_10
Version 5.003_11
Version 5.003_12
Version 5.003_13
Version 5.003_14
Version 5.003_15
Version 5.003_16
Version 5.003_17
Version 5.003_18
Version 5.003_19
Version 5.003_20
Version 5.003_21
Version 5.003_22
Version 5.003_23
Version 5.003_24
Version 5.003_25
Version 5.003_26
Version 5.003_27
Version 5.003_28
Version 5.003_90
Version 5.003_91
Version 5.003_92
Version 5.003_93
Version 5.003_94
Version 5.003_95
Version 5.003_96
Version 5.003_97
Version 5.003_97a
Version 5.003_97b
Version 5.003_97c
Version 5.003_97d
Version 5.003_97e
Version 5.003_97f
Version 5.003_97g
Version 5.003_97h
Version 5.003_97i
Version 5.003_97j
Version 5.003_98
Version 5.003_99
Version 5.003_99a
Version 5.004
Version 5.004_01
Version 5.004_02
Version 5.004_03
Version 5.004_04
Version 5.004_05
Version 5.005
Version 5.005_01
Version 5.005_02
Version 5.005_03
Version 5.005_04
Version 5.10.0
Version 5.10.1
Version 5.10.1 rc1
Version 5.10.1 rc2
Version 5.10
Version 5.11.0
Version 5.11.1
Version 5.11.2
Version 5.11.3
Version 5.11.4
Version 5.11.5
Version 5.12.0
Version 5.12.0 rc0
Version 5.12.0 rc1
Version 5.12.0 rc2
Version 5.12.0 rc3
Version 5.12.0 rc4
Version 5.12.0 rc5
Version 5.12.1
Version 5.12.1 rc0
Version 5.12.1 rc1
Version 5.12.1 rc2
Version 5.12.2
Version 5.12.2 rc1
Version 5.12.3
Version 5.12.3 rc1
Version 5.12.3 rc2
Version 5.12.3 rc3
Version 5.12.4
Version 5.12.4 rc1
Version 5.12.4 rc2
Version 5.12.5
Version 5.12.5 rc1
Version 5.12.5 rc2
Version 5.13.0
Version 5.13.10
Version 5.13.11
Version 5.13.1
Version 5.13.2
Version 5.13.3
Version 5.13.4
Version 5.13.5
Version 5.13.6
Version 5.13.7
Version 5.13.8
Version 5.13.9
Version 5.14.0
Version 5.14.0 rc1
Version 5.14.0 rc2
Version 5.14.0 rc3
Version 5.14.1
Version 5.14.1 rc1
Version 5.14.2
Version 5.14.2 rc1
Version 5.14.3
Version 5.14.3 rc1
Version 5.14.3 rc2
Version 5.14.4
Version 5.14.4 rc1
Version 5.14.4 rc2
Version 5.15.0
Version 5.15.1
Version 5.15.2
Version 5.15.3
Version 5.15.4
Version 5.15.5
Version 5.15.6
Version 5.15.7
Version 5.15.8
Version 5.15.9
Version 5.16.0
Version 5.16.0 rc1
Version 5.16.0 rc2
Version 5.16.1
Version 5.16.2
Version 5.16.3
Version 5.16.3 rc1
Version 5.17.0
Version 5.17.10
Version 5.17.11
Version 5.17.1
Version 5.17.2
Version 5.17.3
Version 5.17.4
Version 5.17.5
Version 5.17.6
Version 5.17.7.0
Version 5.17.7
Version 5.17.8
Version 5.17.9
Version 5.18.0
Version 5.18.0 rc1
Version 5.18.0 rc2
Version 5.18.0 rc3
Version 5.18.0 rc4
Version 5.18.1
Version 5.18.2
Version 5.18.2 rc1
Version 5.18.2 rc2
Version 5.18.2 rc3
Version 5.18.2 rc4
Version 5.18.3
Version 5.18.3 rc1
Version 5.18.3 rc2
Version 5.18.4
Version 5.19.0
Version 5.19.10
Version 5.19.11
Version 5.19.1
Version 5.19.2
Version 5.19.3
Version 5.19.4
Version 5.19.5
Version 5.19.6
Version 5.19.7
Version 5.19.8
Version 5.19.9
Version 5.20.0
Version 5.20.0 rc1
Version 5.20.1
Version 5.20.1 rc1
Version 5.20.1 rc2
Version 5.20.2
Version 5.20.2 rc1
Version 5.20.3
Version 5.20.3 rc1
Version 5.20.3 rc2
Version 5.21.0
Version 5.21.10
Version 5.21.11
Version 5.21.1
Version 5.21.2
Version 5.21.3
Version 5.21.4
Version 5.21.5
Version 5.21.6
Version 5.21.7
Version 5.21.8
Version 5.21.9
Version 5.22.0
Version 5.22.0 rc1
Version 5.22.0 rc2
Version 5.22.1
Version 5.22.1 rc1
Version 5.22.1 rc2
Version 5.22.1 rc3
Version 5.22.1 rc4
Version 5.22.2
Version 5.22.2 rc1
Version 5.22.3 rc1
Version 5.24.0
Version 5.24.0 rc1
Version 5.24.0 rc2
Version 5.24.0 rc3
Version 5.24.0 rc4
Version 5.24.0 rc5
Version 5.24.1 rc1
Version 5.6.0
Version 5.6.1
Version 5.6.2
Version 5.6
Version 5.7.3
Version 5.8.0
Version 5.8.1
Version 5.8.2
Version 5.8.3
Version 5.8.4
Version 5.8.5
Version 5.8.6
Version 5.8.7
Version 5.8.8
Version 5.8.9
Version 5.8.9 rc1
Version 5.8
Version 5.9.0
Version 5.9.1
Version 5.9.2
Version 5.9.3
Version 5.9.4
Version 5.9.5
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 15.0
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.4.2

Related CWEs

References (30)

Source: security@debian.org
Third Party Advisory
Source: security@debian.org
Third Party AdvisoryVDB Entry
Source: security@debian.org
Third Party AdvisoryVDB Entry
Source: security@debian.org
Mailing ListThird Party Advisory
Source: security@debian.org
Permissions Required
Source: security@debian.org
Third Party Advisory
Source: security@debian.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.