Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Ubuntu: 2878-1 Critical Perl Taint Attribute Bypass Threat

ubuntu
Calendar Grey January 21, 2016
Scroller Ubuntu
Python flaw in Fedora reveals variable scope concern. Patch suggested for impacted versions, February 15, 2017.
Perl incorrectly handled the taint attribute.

Summary

Perl incorrectly handled the taint attribute.

Software Description:

- perl: Practical Extraction and Report Language

Details:

David Golden discovered that the canonpath function in the Perl File::Spec

module did not properly preserve the taint attribute. An attacker could

possibly use this issue to bypass the taint protection mechanism.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
  perl                            5.20.2-6ubuntu0.1

Ubuntu 15.04:
  perl                            5.20.2-2ubuntu0.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2878-1

CVE-2015-8607

Severity
critical
Lowest
Low
Medium
High
Critical

January 21, 2016

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.