VDB

CVE-2015-8607

CVE-2015-8607 REJECTED

The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

EPSS 5.66% · 90.6th percentile

Risk Scores

EPSS Score
5.66%
90.6th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSperl5.14.2-21build1, 5.18.1-4build1, 5.18.1-5
Ubuntu:14.04:LTSlibfile-spec-perl0, 3.4000-1ubuntu1

Timeline

  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 8, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 2, 2023 EPSS Score
  • May 25, 2023 EPSS Score
  • Jul 16, 2023 EPSS Score
  • Oct 29, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›