VYPR

rpm package

almalinux/perl-CPAN

pkg:rpm/almalinux/perl-CPAN

Vulnerabilities (7)

  • CVE-2026-48962HigMay 27, 2026
    affected < 2.28-5.module_el8.6.0+2766+8bf0b7cefixed 2.28-5.module_el8.6.0+2766+8bf0b7ce

    IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored

  • CVE-2026-9538HigMay 26, 2026
    affected < 2.28-5.module_el8.6.0+2766+8bf0b7cefixed 2.28-5.module_el8.6.0+2766+8bf0b7ce

    Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header wit

  • CVE-2026-42496CriMay 26, 2026
    affected < 2.28-5.module_el8.6.0+2766+8bf0b7cefixed 2.28-5.module_el8.6.0+2766+8bf0b7ce

    Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode

  • CVE-2025-40909MedMay 30, 2025
    affected < 2.28-5.module_el8.6.0+2766+8bf0b7cefixed 2.28-5.module_el8.6.0+2766+8bf0b7ce

    Perl threads have a working directory race condition where file operations may target unintended paths. If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is

  • CVE-2023-47038HigDec 18, 2023
    affected < 2.28-5.module_el8.6.0+2766+8bf0b7cefixed 2.28-5.module_el8.6.0+2766+8bf0b7ce

    A vulnerability was found in perl 5.30.0 through 5.38.0. This issue occurs when a crafted regular expression is compiled by perl, which can allow an attacker controlled byte buffer overflow in a heap allocated buffer.

  • CVE-2023-31484HigApr 29, 2023
    affected < 2.29-3.el9fixed 2.29-3.el9

    CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.

  • CVE-2020-16156HigDec 13, 2021
    affected < 2.18-402.el8_10fixed 2.18-402.el8_10

    CPAN 2.28 allows Signature Verification Bypass.