CVE-2021-36770

Name
CVE-2021-36770
Description
Encode.pm, as distributed in Perl through 5.34.0, allows local users to gain privileges via a Trojan horse Encode::ConfigLocal library (in the current working directory) that preempts dynamic module loading. Exploitation requires an unusual configuration, and certain 2021 versions of Encode.pm (3.05 through 3.11). This issue occurs because the || operator evaluates @INC in a scalar context, and thus @INC has only an integer value.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://security-tracker.debian.org/tracker/CVE-2021-36770
CONFIRM https://github.com/Perl/perl5/commit/c1a937fef07c061600a0078f4cb53fe9c2136bb9
CONFIRM https://news.cpanel.com/unscheduled-tsr-10-august-2021/
CONFIRM https://metacpan.org/dist/Encode/changes
CONFIRM https://github.com/dankogai/p5-encode/commit/527e482dc70b035d0df4f8c77a00d81f8d775c74
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6KOZYD7BH2DNIAEZ2ZL4PJ4QUVQI6Y33/
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5NDGQSGMEZ75FJGBKNYC75OTO7TF7XHB/
Third Party Advisory https://security.netapp.com/advisory/ntap-20210909-0003/
cve@mitre.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5NDGQSGMEZ75FJGBKNYC75OTO7TF7XHB/
cve@mitre.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6KOZYD7BH2DNIAEZ2ZL4PJ4QUVQI6Y33/
af854a3a-2127-422b-91ae-364da2661108 https://security.netapp.com/advisory/ntap-20241108-0002/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:p5-encode_project:p5-encode:*:*:*:*:*:*:*:* p5-encode >= 3.05 < 3.12

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
perl-encode edge-main 3.12-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
perl-encode 3.22-main 3.12-r0 None fixed
perl-encode 3.21-main 3.12-r0 None fixed
perl-encode 3.20-main 3.12-r0 None fixed
perl-encode 3.19-main 3.12-r0 None fixed
perl-encode 3.18-main 3.12-r0 None fixed
perl-encode 3.17-main 3.12-r0 None fixed
perl edge-main 5.34.0-r1 Natanael Copa <ncopa@alpinelinux.org> fixed
perl 3.22-main 5.34.0-r1 None fixed
perl 3.21-main 5.34.0-r1 None fixed
perl 3.20-main 5.34.0-r1 None fixed
perl 3.19-main 5.34.0-r1 None fixed
perl 3.18-main 5.34.0-r1 None fixed
perl 3.17-main 5.34.0-r1 None fixed