CVE-2016-2381

Published on: 04/08/2016 12:00:00 AM UTC

Last Modified on: 03/23/2021 11:27:15 PM UTC

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Certain versions of Ubuntu Linux from Canonical contain the following vulnerability:

Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.

  • CVE-2016-2381 has been assigned by [email protected] to track the vulnerability - currently rated as HIGH severity.

CVSS3 Score: 7.5 - HIGH

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
NETWORK LOW NONE NONE
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED NONE HIGH NONE

CVSS2 Score: 5 - MEDIUM

Access
Vector
Access
Complexity
Authentication
NETWORK LOW NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
NONE PARTIAL NONE

CVE References

Description Tags Link
Debian -- Security Information -- DSA-3501-1 perl Third Party Advisory
www.debian.org
Depreciated Link
text/html
URL Logo DEBIAN DSA-3501
Oracle Critical Patch Update Advisory - July 2020 Third Party Advisory
www.oracle.com
text/html
URL Logo MISC www.oracle.com/security-alerts/cpujul2020.html
AWS, Azure, Managed Cloud & Security in Canada | Carbon60 Third Party Advisory
www.gossamer-threads.com
text/html
URL Logo MLIST [porters] 20160301 CVE-2016-2381: duplicate environment variables
Perl 'perl.c' CVE-2016-2381 Security Bypass Vulnerability Third Party Advisory
VDB Entry
cve.report (archive)
text/html
URL Logo BID 83802
Document Display | HPE Support Center Third Party Advisory
h20566.www2.hpe.com
text/html
URL Logo CONFIRM h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05240731
USN-2916-1: Perl vulnerabilities | Ubuntu Third Party Advisory
www.ubuntu.com
text/html
URL Logo UBUNTU USN-2916-1
Perl: Multiple vulnerabilities (GLSA 201701-75) — Gentoo security Third Party Advisory
security.gentoo.org
text/html
URL Logo GENTOO GLSA-201701-75
openSUSE-SU-2016:0881-1: moderate: Security update for perl Mailing List
Third Party Advisory
lists.opensuse.org
text/html
URL Logo SUSE openSUSE-SU-2016:0881
perl5.git.perl.org Git Vendor Advisory
perl5.git.perl.org
text/xml
URL Logo CONFIRM perl5.git.perl.org/perl.git/commitdiff/ae37b791a73a9e78dedb89fb2429d2628cf58076
Oracle Critical Patch Update Advisory - April 2020 Third Party Advisory
www.oracle.com
text/html
URL Logo N/A N/A
Oracle Critical Patch Update - July 2017 Third Party Advisory
www.oracle.com
text/html
URL Logo CONFIRM www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
Oracle Critical Patch Update - October 2017 Third Party Advisory
www.oracle.com
text/html
URL Logo CONFIRM www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
Oracle Solaris Bulletin - July 2016 Third Party Advisory
www.oracle.com
text/html
URL Logo CONFIRM www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
Operating
System
CanonicalUbuntu Linux12.04AllAllAll
Operating
System
CanonicalUbuntu Linux14.04AllAllAll
Operating
System
CanonicalUbuntu Linux15.10AllAllAll
Operating
System
CanonicalUbuntu Linux12.04AllAllAll
Operating
System
CanonicalUbuntu Linux14.04AllAllAll
Operating
System
CanonicalUbuntu Linux15.10AllAllAll
Operating
System
DebianDebian Linux7.0AllAllAll
Operating
System
DebianDebian Linux8.0AllAllAll
Operating
System
DebianDebian Linux7.0AllAllAll
Operating
System
DebianDebian Linux8.0AllAllAll
Operating
System
OpensuseOpensuse13.2AllAllAll
Operating
System
OpensuseOpensuse13.2AllAllAll
ApplicationOracleCommunications Billing And Revenue Management7.5AllAllAll
ApplicationOracleCommunications Billing And Revenue Management7.5AllAllAll
ApplicationOracleConfiguration ManagerAllAllAllAll
ApplicationOracleConfiguration Manager12.1.2.0.6AllAllAll
ApplicationOracleConfiguration ManagerAllAllAllAll
ApplicationOracleConfiguration Manager12.1.2.0.6AllAllAll
ApplicationOracleDatabase Server11.2.0.4AllAllAll
ApplicationOracleDatabase Server12.1.0.2AllAllAll
ApplicationOracleDatabase Server12.2.0.1AllAllAll
ApplicationOracleDatabase Server18cAllAllAll
ApplicationOracleDatabase Server19cAllAllAll
ApplicationOracleDatabase Server11.2.0.4AllAllAll
ApplicationOracleDatabase Server12.1.0.2AllAllAll
ApplicationOracleDatabase Server12.2.0.1AllAllAll
ApplicationOracleDatabase Server18cAllAllAll
ApplicationOracleDatabase Server19cAllAllAll
ApplicationOracleEnterprise Manager Base Platform13.2.0.0.0AllAllAll
ApplicationOracleEnterprise Manager Base Platform13.3.0.0.0AllAllAll
ApplicationOracleEnterprise Manager Base Platform13.2.0.0.0AllAllAll
ApplicationOracleEnterprise Manager Base Platform13.3.0.0.0AllAllAll
Operating
System
OracleSolaris11.3AllAllAll
Operating
System
OracleSolaris11.3AllAllAll
ApplicationOracleTimesten In-memory DatabaseAllAllAllAll
ApplicationOracleTimesten In-memory DatabaseAllAllAllAll
ApplicationPerlPerlAllAllAllAll
ApplicationPerlPerlAllAllAllAll
  • cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*:
  • cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*:
  • cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*:
  • cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*:
  • cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*:
  • cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*:
  • cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*:
  • cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:communications_billing_and_revenue_management:7.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:communications_billing_and_revenue_management:7.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:configuration_manager:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:configuration_manager:12.1.2.0.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:configuration_manager:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:configuration_manager:12.1.2.0.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:database_server:11.2.0.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:database_server:12.1.0.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:database_server:12.2.0.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:database_server:18c:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:database_server:19c:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:database_server:11.2.0.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:database_server:12.1.0.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:database_server:12.2.0.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:database_server:18c:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:database_server:19c:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:enterprise_manager_base_platform:13.2.0.0.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:enterprise_manager_base_platform:13.3.0.0.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:enterprise_manager_base_platform:13.2.0.0.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:enterprise_manager_base_platform:13.3.0.0.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*:
  • cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:timesten_in-memory_database:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:timesten_in-memory_database:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:perl:perl:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:perl:perl:*:*:*:*:*:*:*:*: