VDB
BDU%3A2025-10307
BDU%3A2025-10307
PUBLISHED
CVSS 4.599999904632568 MEDIUM
Уязвимость интерпретатора языка программирования Perl, связанная с использованием ненадёжного пути поиска, позволяющая нарушителю выполнить произвольный код или получить несанкционированный доступ к защищаемой информации
Risk Scores
CVSS 2.0
4.599999904632568
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», ООО «РусБИТех-Астра», Canonical Ltd., ООО «НЦПР» | Red Hat Enterprise Linux, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), Astra Linux Special Edition (запись в едином реестре российских программ №369), Ubuntu, Perl, Red Hat Discovery, МСВСфера |
Timeline
- Aug 27, 2025 CVE Published
- Feb 16, 2026 CVE Updated
References
- https://github.com/Perl/perl5/commit/918bfff86ca8d6d4e4ec5b30994451e0bd74aba9.patch url
- https://wiki.astralinux.ru/astra-linux-se18-bulletin-2025-0811SE18 url
- https://wiki.astralinux.ru/astra-linux-se38-bulletin-2026-0126SE38 url
- https://www.openwall.com/lists/oss-security/2025/05/30/4 advisory
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory
- https://ubuntu.com/security/CVE-2025-40909 advisory
- https://errata.msvsphere-os.ru/definition/9/INFCSA-2025:11804?lang=ru advisory
- https://access.redhat.com/security/cve/cve-2025-40909 url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2025-1020SE47 url
- https://github.com/Perl/perl5/issues/23010 advisory
- https://github.com/Perl/perl5/commit/11a11ecf4bea72b17d250cfb43c897be1341861e advisory
- https://github.com/Perl/perl5/issues/10387 advisory
- https://security-tracker.debian.org/tracker/CVE-2025-40909 advisory
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2025-0923SE17 advisory