CVE-2021-36770

NameCVE-2021-36770
DescriptionEncode.pm, as distributed in Perl through 5.34.0, allows local users t ...
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libencode-perl (PTS)bullseye3.08-1+deb11u2fixed
bullseye (security)3.08-1+deb11u1fixed
bookworm3.19-1fixed
forky, sid, trixie3.21-1fixed
perl (PTS)bullseye5.32.1-4+deb11u3fixed
bullseye (security)5.32.1-4+deb11u5fixed
bookworm5.36.0-7+deb12u3fixed
bookworm (security)5.36.0-7+deb12u2fixed
trixie5.40.1-6fixed
forky, sid5.40.1-7fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libencode-perlsourcestretch(not affected)
libencode-perlsourcebuster(not affected)
libencode-perlsourcebullseye3.08-1+deb11u1
libencode-perlsource(unstable)3.08-2
perlsourcestretch(not affected)
perlsourcebuster(not affected)
perlsourcebullseye5.32.1-4+deb11u1
perlsource(unstable)5.32.1-5

Notes

[buster] - libencode-perl <not-affected> (Vulnerable code introduced later)
[stretch] - libencode-perl <not-affected> (Vulnerable code introduced later)
[buster] - perl <not-affected> (Vulnerable code introduced later)
[stretch] - perl <not-affected> (Vulnerable code introduced later)
Introduced by: https://github.com/dankogai/p5-encode/commit/9c5f5a307863b66da3701f6c7d13139aa20179b8 (3.05)
Fixed by: https://github.com/dankogai/p5-encode/commit/527e482dc70b035d0df4f8c77a00d81f8d775c74 (3.12)
Introduced by: https://github.com/Perl/perl5/commit/8ced1423dbb2a874f2d95e9c5c4c46960c2bf318 (v5.32.0-RC0)
Fixed by: https://github.com/Perl/perl5/commit/c1a937fef07c061600a0078f4cb53fe9c2136bb9

Search for package or bug name: Reporting problems