Vulnerability Bulletins

DSA-3501 perl - security update

   
Affected software Debian
 
Stephane Chazelas discovered a bug in the environment handling in Perl.Perl provides a Perl-space hash variable, %ENV, in which environmentvariables can be looked up. If a variable appears twice in envp, onlythe last value would appear in %ENV, but getenv would return the first.Perls taint security mechanism would be applied to the value in %ENV,but not to the other rest of the environment. This could result in anambiguous environment causing environment variables to be propagated

More info:

https://www.debian.org/security/2016/dsa-3501