CVE-2016-6185 PUBLISHED

The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execute arbitrary code via a Trojan horse library under the current working directory.

EPSS 0.25% · 47.6th percentile

Risk Scores

EPSS Score
0.25%
47.6th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSperl5.22.1-9ubuntu0.2, 0, 5.20.2-6
Ubuntu:14.04:LTSperl0, 5.14.2-21build1, 5.18.1-4

Timeline

References

Open in Interactive Console →