vendor:
Perl
by:
Kevin Finisterre
7.5
CVSS
HIGH
PERLIO_DEBUG vulnerability
119
CWE
Product Name: Perl
Affected Version From: sperl5.8.4
Affected Version To: sperl5.8.4
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Debian
2005
Setuid Perl exploit
This exploit takes advantage of a vulnerability in the PERLIO_DEBUG functionality. It allows an attacker to overwrite the /etc/ld.so.preload file and gain root privileges on the targeted system.
Mitigation:
To mitigate this vulnerability, ensure that the PERLIO_DEBUG functionality is disabled or not accessible to untrusted users. Additionally, monitor the /etc/ld.so.preload file for any unauthorized changes.