CVE-2021-36770

NameCVE-2021-36770
DescriptionEncode.pm, as distributed in Perl through 5.34.0, allows local users to gain privileges via a Trojan horse Encode::ConfigLocal library (in the current working directory) that preempts dynamic module loading. Exploitation requires an unusual configuration, and certain 2021 versions of Encode.pm (3.05 through 3.11). This issue occurs because the || operator evaluates @INC in a scalar context, and thus @INC has only an integer value.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libencode-perl (PTS)jessie2.63-1+deb8u1vulnerable
stretch2.88-1fixed
buster3.00-1+deb10u1fixed
bullseye3.08-1+deb11u2fixed
bullseye (security)3.08-1+deb11u1fixed
bookworm3.19-1fixed
sid, trixie3.21-1fixed
perl (PTS)jessie, jessie (lts)5.20.2-3+deb8u14fixed
stretch (security)5.24.1-3+deb9u5fixed
stretch (lts), stretch5.24.1-3+deb9u8fixed
buster, buster (lts)5.28.1-6+deb10u2fixed
bullseye5.32.1-4+deb11u3fixed
bullseye (security)5.32.1-4+deb11u4fixed
bookworm5.36.0-7+deb12u1fixed
sid, trixie5.40.0-7fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libencode-perlsourcejessie(unfixed)end-of-life
libencode-perlsourcestretch(not affected)
libencode-perlsourcebuster(not affected)
libencode-perlsourcebullseye3.08-1+deb11u1
libencode-perlsource(unstable)3.08-2
perlsourcejessie(not affected)
perlsourcestretch(not affected)
perlsourcebuster(not affected)
perlsourcebullseye5.32.1-4+deb11u1
perlsource(unstable)5.32.1-5

Notes

[buster] - libencode-perl <not-affected> (Vulnerable code introduced later)
[stretch] - libencode-perl <not-affected> (Vulnerable code introduced later)
[buster] - perl <not-affected> (Vulnerable code introduced later)
[stretch] - perl <not-affected> (Vulnerable code introduced later)
Introduced by: https://github.com/dankogai/p5-encode/commit/9c5f5a307863b66da3701f6c7d13139aa20179b8 (3.05)
Fixed by: https://github.com/dankogai/p5-encode/commit/527e482dc70b035d0df4f8c77a00d81f8d775c74 (3.12)
Introduced by: https://github.com/Perl/perl5/commit/8ced1423dbb2a874f2d95e9c5c4c46960c2bf318 (v5.32.0-RC0)
Fixed by: https://github.com/Perl/perl5/commit/c1a937fef07c061600a0078f4cb53fe9c2136bb9
[jessie] - perl <not-affected> (Vulnerable code introduced later)

Search for package or bug name: Reporting problems