Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24751
HistoryApr 10, 2020 - 1:03 a.m.

Arbitrary Code Execution

2020-04-1001:03:28
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.036 Low

EPSS

Percentile

91.6%

perl is vulnerable to arbitrary code execution. It was found that the “new” constructor of the Digest module used its argument as part of the string expression passed to the eval() function. An attacker could possibly use this flaw to execute arbitrary Perl code with the privileges of a Perl program that uses untrusted input as an argument to the constructor.