CVE-2016-1238

high
Published 2016-08-02 ยท Modified 2026-05-06
CVSS v3
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
7.8

Description

(1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6) cpan/Encode/bin/enc2xs, (7) cpan/Encode/bin/encguess, (8) cpan/Encode/bin/piconv, (9) cpan/Encode/bin/ucmlint, (10) cpan/Encode/bin/unidump, (11) cpan/ExtUtils-MakeMaker/bin/instmodsh, (12) cpan/IO-Compress/bin/zipdetails, (13) cpan/JSON-PP/bin/json_pp, (14) cpan/Test-Harness/bin/prove, (15) dist/ExtUtils-ParseXS/lib/ExtUtils/xsubpp, (16) dist/Module-CoreList/corelist, (17) ext/Pod-Html/bin/pod2html, (18) utils/c2ph.PL, (19) utils/h2ph.PL, (20) utils/h2xs.PL, (21) utils/libnetcfg.PL, (22) utils/perlbug.PL, (23) utils/perldoc.PL, (24) utils/perlivp.PL, and (25) utils/splain.PL in Perl 5.x before 5.22.3-RC2 and 5.24 before 5.24.1-RC2 do not properly remove . (period) characters from the end of the includes directory array, which might allow local users to gain privileges via a Trojan horse module under the current working directory.

Predictions

Exploit likelihood
75%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

OSVersionStatusFixed in
suse slesaffected
fedora fedora23affected
fedora fedora24affected
suse suse15.0affected
debian debian8.0affected
debian debianbookwormfixed5.22.2-3
debian debianbullseyefixed5.22.2-3
debian debianforkyfixed5.22.2-3
debian debiansidfixed5.22.2-3
debian debiantrixiefixed5.22.2-3

Application impact

VendorProductVersionsFixed
perlperl5.13.10
perlperl1.0.15
perlperl1.0.16
perlperl5.000
perlperl5.000o
perlperl5.001
perlperl5.001n
perlperl5.002
perlperl5.002_01
perlperl5.003
perlperl5.003_01
perlperl5.003_02
perlperl5.003_03
perlperl5.003_04
perlperl5.003_05
perlperl5.003_07
perlperl5.003_08
perlperl5.003_09
perlperl5.003_10
perlperl5.003_11
perlperl5.003_12
perlperl5.003_13
perlperl5.003_14
perlperl5.003_15
perlperl5.003_16
perlperl5.003_17
perlperl5.003_18
perlperl5.003_19
perlperl5.003_20
perlperl5.003_21
perlperl5.003_22
perlperl5.003_23
perlperl5.003_24
perlperl5.003_25
perlperl5.003_26
perlperl5.003_27
perlperl5.003_28
perlperl5.003_90
perlperl5.003_91
perlperl5.003_92
perlperl5.003_93
perlperl5.003_94
perlperl5.003_95
perlperl5.003_96
perlperl5.003_97
perlperl5.003_97a
perlperl5.003_97b
perlperl5.003_97c
perlperl5.003_97d
perlperl5.003_97e
perlperl5.003_97f
perlperl5.003_97g
perlperl5.003_97h
perlperl5.003_97i
perlperl5.003_97j
perlperl5.003_98
perlperl5.003_99
perlperl5.003_99a
perlperl5.004
perlperl5.004_01
perlperl5.004_02
perlperl5.004_03
perlperl5.004_04
perlperl5.004_05
perlperl5.005
perlperl5.005_01
perlperl5.005_02
perlperl5.005_03
perlperl5.005_04
perlperl5.6
perlperl5.6.0
perlperl5.6.1
perlperl5.6.2
perlperl5.7.3
perlperl5.8
perlperl5.8.0
perlperl5.8.1
perlperl5.8.2
perlperl5.8.3
perlperl5.8.4
perlperl5.8.5
perlperl5.8.6
perlperl5.8.7
perlperl5.8.8
perlperl5.8.9
perlperl5.9.0
perlperl5.9.1
perlperl5.9.2
perlperl5.9.3
perlperl5.9.4
perlperl5.9.5
perlperl5.10
perlperl5.10.0
perlperl5.10.1
perlperl5.11.0
perlperl5.11.1
perlperl5.11.2
perlperl5.11.3
perlperl5.11.4
perlperl5.11.5
perlperl5.12.0
perlperl5.12.1
perlperl5.12.2
perlperl5.12.3
perlperl5.12.4
perlperl5.12.5
perlperl5.13.0
perlperl5.13.1
perlperl5.13.2
perlperl5.13.3
perlperl5.13.4
perlperl5.13.5
perlperl5.13.6
perlperl5.13.7
perlperl5.13.8
perlperl5.13.9
perlperl5.13.11
perlperl5.14.0
perlperl5.14.1
perlperl5.14.2
perlperl5.14.3
perlperl5.14.4
perlperl5.15.0
perlperl5.15.1
perlperl5.15.2
perlperl5.15.3
perlperl5.15.4
perlperl5.15.5
perlperl5.15.6
perlperl5.15.7
perlperl5.15.8
perlperl5.15.9
perlperl5.16.0
perlperl5.16.1
perlperl5.16.2
perlperl5.16.3
perlperl5.17.0
perlperl5.17.1
perlperl5.17.2
perlperl5.17.3
perlperl5.17.4
perlperl5.17.5
perlperl5.17.6
perlperl5.17.7
perlperl5.17.7.0
perlperl5.17.8
perlperl5.17.9
perlperl5.17.10
perlperl5.17.11
perlperl5.18.0
perlperl5.18.1
perlperl5.18.2
perlperl5.18.3
perlperl5.18.4
perlperl5.19.0
perlperl5.19.1
perlperl5.19.2
perlperl5.19.3
perlperl5.19.4
perlperl5.19.5
perlperl5.19.6
perlperl5.19.7
perlperl5.19.8
perlperl5.19.9
perlperl5.19.10
perlperl5.19.11
perlperl5.20.0
perlperl5.20.1
perlperl5.20.2
perlperl5.20.3
perlperl5.21.0
perlperl5.21.1
perlperl5.21.2
perlperl5.21.3
perlperl5.21.4
perlperl5.21.5
perlperl5.21.6
perlperl5.21.7
perlperl5.21.8
perlperl5.21.9
perlperl5.21.10
perlperl5.21.11
perlperl5.22.0
perlperl5.22.1
perlperl5.22.2
perlperl5.22.3
perlperl5.24.0
perlperl5.24.1
apache apachespamassassin{"endExcluding":"3.4.2"}3.4.2

References

CWEs

CWE-264

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.