CVE-2016-1238

HIGHCVSS 7.8/10EPSS 0.78%

Last modified

CVE-2016-1238 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. (1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6) cpan/Encode/bin/enc2xs, (7) cpan/Encode/bin/encguess, (8) cpan/Encode/bin/piconv, (9) cpan/Encode/bin/ucmlint, (10) cpan/Encode/bin/unidump, (11) cpan/ExtUtils-MakeMaker/bin/instmodsh, (12) cpan/IO-Compress/bin/zipdetails, (13) cpan/JSON-PP/bin/json_pp, (14) cpan/Test-Harness/bin/prove, (15) dist/ExtUtils-ParseXS/lib/ExtUtils/xsubpp, (16) dist/Module-CoreList/corelist, (17) ext/Pod-Html/bin/pod2html, (18) utils/c2ph.PL, (19) utils/h2ph.PL, (20) utils/h2xs.PL, (21) utils/libnetcfg.PL, (22) utils/perlbug.PL, (23) utils/perldoc.PL, (24) utils/perlivp.PL, and (25) utils/splain.PL in Perl 5.x before 5.22.3-RC2 and 5.24 before 5.24.1-RC2 do not properly remove . (period) characters from the end of the includes directory array, which might allow local users to gain privileges via a Trojan horse module under the current working directory.. EPSS estimates a 0.78% chance of exploitation in the next 30 days.

Description

(1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6) cpan/Encode/bin/enc2xs, (7) cpan/Encode/bin/encguess, (8) cpan/Encode/bin/piconv, (9) cpan/Encode/bin/ucmlint, (10) cpan/Encode/bin/unidump, (11) cpan/ExtUtils-MakeMaker/bin/instmodsh, (12) cpan/IO-Compress/bin/zipdetails, (13) cpan/JSON-PP/bin/json_pp, (14) cpan/Test-Harness/bin/prove, (15) dist/ExtUtils-ParseXS/lib/ExtUtils/xsubpp, (16) dist/Module-CoreList/corelist, (17) ext/Pod-Html/bin/pod2html, (18) utils/c2ph.PL, (19) utils/h2ph.PL, (20) utils/h2xs.PL, (21) utils/libnetcfg.PL, (22) utils/perlbug.PL, (23) utils/perldoc.PL, (24) utils/perlivp.PL, and (25) utils/splain.PL in Perl 5.x before 5.22.3-RC2 and 5.24 before 5.24.1-RC2 do not properly remove . (period) characters from the end of the includes directory array, which might allow local users to gain privileges via a Trojan horse module under the current working directory.

Metrics

EPSS Probability
0.78%

51.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
DebianDebian Linux8.0—
FedoraprojectFedora23—
FedoraprojectFedora24—
PerlPerl1.0.15—
PerlPerl1.0.16—
PerlPerl5.000—
PerlPerl5.000o—
PerlPerl5.001—
PerlPerl5.001n—
PerlPerl5.002—
PerlPerl5.002_01—
PerlPerl5.003—
PerlPerl5.003_01—
PerlPerl5.003_02—
PerlPerl5.003_03—
PerlPerl5.003_04—
PerlPerl5.003_05—
PerlPerl5.003_07—
PerlPerl5.003_08—
PerlPerl5.003_09—
PerlPerl5.003_10—
PerlPerl5.003_11—
PerlPerl5.003_12—
PerlPerl5.003_13—
PerlPerl5.003_14—
PerlPerl5.003_15—
PerlPerl5.003_16—
PerlPerl5.003_17—
PerlPerl5.003_18—
PerlPerl5.003_19—
PerlPerl5.003_20—
PerlPerl5.003_21—
PerlPerl5.003_22—
PerlPerl5.003_23—
PerlPerl5.003_24—
PerlPerl5.003_25—
PerlPerl5.003_26—
PerlPerl5.003_27—
PerlPerl5.003_28—
PerlPerl5.003_90—
PerlPerl5.003_91—
PerlPerl5.003_92—
PerlPerl5.003_93—
PerlPerl5.003_94—
PerlPerl5.003_95—
PerlPerl5.003_96—
PerlPerl5.003_97—
PerlPerl5.003_97a—
PerlPerl5.003_97b—
PerlPerl5.003_97c—

Showing 50 of 193 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2016-1238?
(1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6) cpan/Encode/bin/enc2xs, (7) cpan/Encode/bin/encguess, (8) cpan/Encode/bin/piconv, (9) cpan/Encode/bin/ucmlint, (10) cpan/Encode/bin/unidump, (11) cpan/ExtUtils-MakeMaker/bin/instmodsh, (12) cpan/IO-Compress/bin/zipdetails, (13) cpan/JSON-PP/bin/json_pp, (14) cpan/Test-Harness/bin/prove, (15) dist/ExtUtils-ParseXS/lib/ExtUtils/xsubpp, (16) dist/Module-CoreList/corelist, (17) ext/Pod-Html/bin/pod2html, (18) utils/c2ph.PL, (19) utils/h2ph.PL, (20) utils/h2xs.PL, (21) utils/libnetcfg.PL, (22) utils/perlbug.PL, (23) utils/perldoc.PL, (24) utils/perlivp.PL, and (25) utils/splain.PL in Perl 5.x before 5.22.3-RC2 and 5.24 before 5.24.1-RC2 do not properly remove . (period) characters from the end of the includes directory array, which might allow local users to gain privileges via a Trojan horse module under the current working directory.
How severe is CVE-2016-1238?
CVE-2016-1238 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.78% probability of exploitation in the next 30 days.
How do I fix CVE-2016-1238?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2016

Are you affected by CVE-2016-1238?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST