CVE-2025-30673

NameCVE-2025-30673
DescriptionSub::HandlesVia for Perl before 0.050002 allows untrusted code from the current working directory ('.') to be loaded similar to CVE-2016-1238. If an attacker can place a malicious file in current working directory, it may be loaded instead of the intended file, potentially leading to arbitrary code execution. Sub::HandlesVia uses Mite to produce the affected code section due to CVE-2025-30672
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libsub-handlesvia-perl (PTS)bullseye0.016-1vulnerable
bookworm0.050000-1vulnerable
trixie0.050000-2vulnerable
sid0.050002-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libsub-handlesvia-perlsource(unstable)0.050002-1

Notes

[bookworm] - libsub-handlesvia-perl <no-dsa> (Minor issue)
https://lists.security.metacpan.org/cve-announce/msg/28383041/
Fixed by: https://github.com/tobyink/p5-sub-handlesvia/commit/9bc3cfb22ade4b407413ae1c746bb331fff52954 (0.050002)

Search for package or bug name: Reporting problems