VDB
CVE-2025-15649
CVE-2025-15649
PUBLISHED
CVSS 5.5 MEDIUM
Reported by CPANSec · Published May 27, 2026
IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date. _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die. The exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError.
Risk Scores
CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| PMQS | IO::Uncompress::Unzip | 0 |
| PMQS | IO::Uncompress::Unzip | 0, 0 |
Timeline
- May 27, 2026 EPSS Score
- May 27, 2026 CVE Published
- May 28, 2026 EPSS Score
- May 28, 2026 Security Advisory
- May 29, 2026 EPSS Score
- May 29, 2026 CVE Updated
- May 30, 2026 EPSS Score
- May 31, 2026 EPSS Score
- Jun 1, 2026 EPSS Score
- Jun 5, 2026 EPSS Score
- Jun 11, 2026 Coalition ESS Score
- Aug 7, 2026 EPSS Score
References
- patch
- issue-tracking
- release-notes
- http://www.openwall.com/lists/oss-security/2026/05/27/1 url