Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
],
"vendor_product": "canonical:ubuntu_linux",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "12.04"
},
{
"last_affected": "14.04"
},
{
"last_affected": "15.10"
}
]
},
{
"cpes": [
"cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*",
"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "debian:debian_linux",
"extracted_events": [
{
"last_affected": "7.0"
},
{
"last_affected": "8.0"
}
]
},
{
"cpes": [
"cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "opensuse:opensuse",
"extracted_events": [
{
"last_affected": "13.2"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:communications_billing_and_revenue_management:7.5:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "oracle:communications_billing_and_revenue_management",
"extracted_events": [
{
"last_affected": "7.5"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:configuration_manager:*:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:configuration_manager:12.1.2.0.6:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "oracle:configuration_manager",
"extracted_events": [
{
"fixed": "12.1.2.0.4"
},
{
"last_affected": "12.1.2.0.6"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:database_server:11.2.0.4:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:database_server:12.1.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:database_server:12.2.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:database_server:18c:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:database_server:19c:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "oracle:database_server",
"extracted_events": [
{
"last_affected": "11.2.0.4"
},
{
"last_affected": "12.1.0.2"
},
{
"last_affected": "12.2.0.1"
},
{
"last_affected": "18c"
},
{
"last_affected": "19c"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:enterprise_manager_base_platform:13.2.0.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:enterprise_manager_base_platform:13.3.0.0.0:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "oracle:enterprise_manager_base_platform",
"extracted_events": [
{
"last_affected": "13.2.0.0.0"
},
{
"last_affected": "13.3.0.0.0"
}
]
},
{
"cpes": [
"cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "oracle:solaris",
"extracted_events": [
{
"last_affected": "11.3"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:timesten_in-memory_database:*:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "oracle:timesten_in-memory_database",
"extracted_events": [
{
"fixed": "18.1.2.1.0"
}
]
}
]
}