In Perl 5.34.0, function Sfinduninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalation.
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "5.34.0-3ubuntu1.3", "binary_name": "libperl-dev" }, { "binary_version": "5.34.0-3ubuntu1.3", "binary_name": "libperl5.34" }, { "binary_version": "5.34.0-3ubuntu1.3", "binary_name": "perl" }, { "binary_version": "5.34.0-3ubuntu1.3", "binary_name": "perl-base" }, { "binary_version": "5.34.0-3ubuntu1.3", "binary_name": "perl-debug" }, { "binary_version": "5.34.0-3ubuntu1.3", "binary_name": "perl-doc" }, { "binary_version": "5.34.0-3ubuntu1.3", "binary_name": "perl-modules-5.34" } ], "priority_reason": "infinite recursion when printing a warning, negligible security impact" }