In Perl 5.34.0, function Sfinduninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalation.
{
"availability": "No subscription required",
"priority_reason": "infinite recursion when printing a warning, negligible security impact",
"binaries": [
{
"binary_name": "libperl-dev",
"binary_version": "5.34.0-3ubuntu1.3"
},
{
"binary_name": "libperl5.34",
"binary_version": "5.34.0-3ubuntu1.3"
},
{
"binary_name": "perl",
"binary_version": "5.34.0-3ubuntu1.3"
},
{
"binary_name": "perl-base",
"binary_version": "5.34.0-3ubuntu1.3"
},
{
"binary_name": "perl-debug",
"binary_version": "5.34.0-3ubuntu1.3"
},
{
"binary_name": "perl-modules-5.34",
"binary_version": "5.34.0-3ubuntu1.3"
}
]
}