CVE-2021-36770
Summary
| CVE | CVE-2021-36770 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-11 23:15:00 UTC |
| Updated | 2023-11-07 03:36:00 UTC |
| Description | Encode.pm, as distributed in Perl through 5.34.0, allows local users to gain privileges via a Trojan horse Encode::ConfigLocal library (in the current working directory) that preempts dynamic module loading. Exploitation requires an unusual configuration, and certain 2021 versions of Encode.pm (3.05 through 3.11). This issue occurs because the || operator evaluates @INC in a scalar context, and thus @INC has only an integer value. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| version 3.12 to address CVE-2021-36770 · dankogai/p5-encode@527e482 · GitHub |
CONFIRM |
github.com |
|
| Encode.pm: apply a local patch for CVE-2021-36770 · Perl/perl5@c1a937f · GitHub |
CONFIRM |
github.com |
|
| [SECURITY] Fedora 34 Update: perl-Encode-3.12-460.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Unscheduled TSR 10 August 2021 | cPanel Newsroom |
CONFIRM |
news.cpanel.com |
|
| [SECURITY] Fedora 33 Update: perl-Encode-3.08-459.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Changes - metacpan.org |
CONFIRM |
metacpan.org |
|
| CVE-2021-36770 |
MISC |
security-tracker.debian.org |
|
| [SECURITY] Fedora 34 Update: perl-Encode-3.12-460.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE-2021-36770 Perl Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| [SECURITY] Fedora 33 Update: perl-Encode-3.08-459.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 180406 Debian Security Update for perllibencode-perl (CVE-2021-36770)
- 198454 Ubuntu Security Notification for Perl vulnerability (USN-5033-1)
- 281799 Fedora Security Update for perl (FEDORA-2021-92e07de1dd)
- 281854 Fedora Security Update for perl (FEDORA-2021-44c65203cc)
- 501990 Alpine Linux Security Update for perl-encode
- 501991 Alpine Linux Security Update for perl
- 504282 Alpine Linux Security Update for perl-encode
- 504288 Alpine Linux Security Update for perl
- 672138 EulerOS Security Update for perl-encode (EulerOS-SA-2022-2420)
- 672142 EulerOS Security Update for perl-encode (EulerOS-SA-2022-2433)