In Perl 5.34.0, function Sfinduninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalation.
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "5.34.0-3ubuntu1.3",
"binary_name": "libperl-dev"
},
{
"binary_version": "5.34.0-3ubuntu1.3",
"binary_name": "libperl5.34"
},
{
"binary_version": "5.34.0-3ubuntu1.3",
"binary_name": "perl"
},
{
"binary_version": "5.34.0-3ubuntu1.3",
"binary_name": "perl-base"
},
{
"binary_version": "5.34.0-3ubuntu1.3",
"binary_name": "perl-debug"
},
{
"binary_version": "5.34.0-3ubuntu1.3",
"binary_name": "perl-modules-5.34"
}
],
"priority_reason": "infinite recursion when printing a warning, negligible security impact"
}