CVE-2016-2381

Description

Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
19.468

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Oracle 11.2.0.4Windows
Multiple Vulnerabilities are affected in Oracle 12.1.0.2Windows
Multiple Vulnerabilities are affected in Oracle 12.2.0.1Windows
Multiple Vulnerabilities are affected in Oracle 18cWindows
Multiple Vulnerabilities are affected in Oracle 19cWindows
Multiple Vulnerabilities are affected in Oracle Database Server 19cWindows
Multiple Vulnerabilities are affected in Oracle Database Server 11.2.0.4Windows
Multiple Vulnerabilities are affected in Oracle Database Server 12.1.0.2Windows
Multiple Vulnerabilities are affected in Oracle Database Server 12.2.0.1Windows
Multiple Vulnerabilities are affected in Oracle Database Server 18cWindows
Practical Extraction and Report Language (USN-2916-1) perl_5.14.2-6ubuntu2.5_i386.debLinux
Practical Extraction and Report Language (USN-2916-1) perl_5.14.2-6ubuntu2.5_amd64.debLinux
Practical Extraction and Report Language (USN-2916-1) perl_5.20.2-6ubuntu0.2_i386.debLinux
Practical Extraction and Report Language (USN-2916-1) perl_5.20.2-6ubuntu0.2_amd64.debLinux
SUSE-SU-2016:2263-1(SUSE Linux Enterprise Desktop 12-SP1 ) perl-5.18.2-11.1.x86_64.rpmLinux
SUSE-SU-2016:2263-1(SUSE Linux Enterprise Desktop 12-SP1 ) perl-32bit-5.18.2-11.1.x86_64.rpmLinux
SUSE-SU-2016:2263-1(SUSE Linux Enterprise Desktop 12-SP1 ) perl-base-5.18.2-11.1.x86_64.rpmLinux
SUSE-SU-2016:2263-1(SUSE Linux Enterprise Desktop 12-SP1 ) perl-base-debuginfo-5.18.2-11.1.x86_64.rpmLinux
SUSE-SU-2016:2263-1(SUSE Linux Enterprise Desktop 12-SP1 ) perl-debuginfo-5.18.2-11.1.x86_64.rpmLinux
SUSE-SU-2016:2263-1(SUSE Linux Enterprise Desktop 12-SP1 ) perl-debuginfo-32bit-5.18.2-11.1.x86_64.rpmLinux
SUSE-SU-2016:2263-1(SUSE Linux Enterprise Desktop 12-SP1 ) perl-debugsource-5.18.2-11.1.x86_64.rpmLinux
SUSE-SU-2016:2263-1(SUSE Linux Enterprise Desktop 12-SP1 ) perl-doc-5.18.2-11.1.noarch.rpmLinux
Improper Input Validation Vulnerability (CVE-2016-2381)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234