Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 8 MGASA-2021-0527 Critical: Perl Encode Privilege Escalation

mageia
Calendar Grey December 2, 2021
Dist Mageia Esm H88
Mageia MGASA-2021-0528 resolves a serious vulnerability in perl-Encode. Discover more about how to protect your environment.
Encode.pm, as distributed in Perl through 5.34.0, allows local users to gain privileges via a Trojan horse Encode::ConfigLocal library (in the current working directory) that preem...

Summary

Encode.pm, as distributed in Perl through 5.34.0, allows local users to gain privileges via a Trojan horse Encode::ConfigLocal library (in the current working directory) that preempts dynamic module loading. Exploitation requires an unusual configuration, and certain 2021 versions of Encode.pm (3.05 through 3.11). This issue occurs because the || operator evaluates @INC in a scalar context, and thus @INC has only an integer value.

References

- https://bugs.mageia.org/show_bug.cgi?id=29352

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/6KOZYD7BH2DNIAEZ2ZL4PJ4QUVQI6Y33/

- https://ubuntu.com/security/notices/USN-5033-1

- https://www.cve.org/CVERecord?id=CVE-2021-36770

Resolution

SRPMS

- 8/core/perl-5.32.1-1.1.mga8

- 8/core/perl-Encode-3.80.0-1.1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 02 Dec 2021
URL: https://advisories.mageia.org/MGASA-2021-0527.html
Type: security
CVE: CVE-2021-36770

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here