CVE-2022-48522

Name
CVE-2022-48522
Description
In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalation.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/Perl/perl5/blob/79a7b254d85a10b65126ad99bf10e70480569d68/sv.c#L16336-L16345

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:perl:perl:5.34.0:-:*:*:*:*:*:* perl == None == 5.34.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
perl 3.15-main 5.34.0-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable