Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 598
Alerts This Week
Warning Icon 1 598

Mageia 8 MGASA-2021-0527 Critical: Perl Encode Privilege Escalation

mageia
Calendar Grey December 2, 2021
Scroller Mageia
Mageia MGASA-2021-0528 resolves a serious vulnerability in perl-Encode. Discover more about how to protect your environment.
Encode.pm, as distributed in Perl through 5.34.0, allows local users to gain privileges via a Trojan horse Encode::ConfigLocal library (in the current working directory) that preem...

Summary

Encode.pm, as distributed in Perl through 5.34.0, allows local users to gain privileges via a Trojan horse Encode::ConfigLocal library (in the current working directory) that preempts dynamic module loading. Exploitation requires an unusual configuration, and certain 2021 versions of Encode.pm (3.05 through 3.11). This issue occurs because the || operator evaluates @INC in a scalar context, and thus @INC has only an integer value.

References

- https://bugs.mageia.org/show_bug.cgi?id=29352

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/6KOZYD7BH2DNIAEZ2ZL4PJ4QUVQI6Y33/

- https://ubuntu.com/security/notices/USN-5033-1

- https://www.cve.org/CVERecord?id=CVE-2021-36770

Resolution

SRPMS

- 8/core/perl-5.32.1-1.1.mga8

- 8/core/perl-Encode-3.80.0-1.1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 02 Dec 2021
URL: https://advisories.mageia.org/MGASA-2021-0527.html
Type: security
CVE: CVE-2021-36770

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.