Amazon Linux AMI update for perl



Risk High
Patch available YES
Number of vulnerabilities 2
CVE-ID CVE-2023-47038
CVE-2023-47100
CWE-ID CWE-193
CWE-20
Exploitation vector Network
Public exploit N/A
Vulnerable software
Amazon Linux AMI
Operating systems & Components / Operating system

perl
Operating systems & Components / Operating system package or component

Vendor Amazon Web Services

Security Bulletin

This security bulletin contains information about 2 vulnerabilities.

1) Off-by-one

EUVDB-ID: #VU83508

Risk: High

CVSSv4.0: 7.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]

CVE-ID: CVE-2023-47038

CWE-ID: CWE-193 - Off-by-one Error

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to an off-by-one error when processing regular expressions. A remote attacker can trigger an off-by-one error and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Update the affected packages:

aarch64:
    perl-Hash-Util-FieldHash-debuginfo-1.20-477.amzn2023.0.6.aarch64
    perl-devel-5.32.1-477.amzn2023.0.6.aarch64
    perl-debugsource-5.32.1-477.amzn2023.0.6.aarch64
    perl-Hash-Util-debuginfo-0.23-477.amzn2023.0.6.aarch64
    perl-Devel-Peek-1.28-477.amzn2023.0.6.aarch64
    perl-B-debuginfo-1.80-477.amzn2023.0.6.aarch64
    perl-NDBM_File-debuginfo-1.15-477.amzn2023.0.6.aarch64
    perl-Devel-Peek-debuginfo-1.28-477.amzn2023.0.6.aarch64
    perl-Time-Piece-debuginfo-1.3401-477.amzn2023.0.6.aarch64
    perl-GDBM_File-1.18-477.amzn2023.0.6.aarch64
    perl-I18N-Langinfo-debuginfo-0.19-477.amzn2023.0.6.aarch64
    perl-IO-1.43-477.amzn2023.0.6.aarch64
    perl-Hash-Util-0.23-477.amzn2023.0.6.aarch64
    perl-POSIX-debuginfo-1.94-477.amzn2023.0.6.aarch64
    perl-IO-debuginfo-1.43-477.amzn2023.0.6.aarch64
    perl-B-1.80-477.amzn2023.0.6.aarch64
    perl-interpreter-5.32.1-477.amzn2023.0.6.aarch64
    perl-Opcode-debuginfo-1.48-477.amzn2023.0.6.aarch64
    perl-File-DosGlob-1.12-477.amzn2023.0.6.aarch64
    perl-Time-Piece-1.3401-477.amzn2023.0.6.aarch64
    perl-mro-1.23-477.amzn2023.0.6.aarch64
    perl-Hash-Util-FieldHash-1.20-477.amzn2023.0.6.aarch64
    perl-tests-5.32.1-477.amzn2023.0.6.aarch64
    perl-libs-5.32.1-477.amzn2023.0.6.aarch64
    perl-NDBM_File-1.15-477.amzn2023.0.6.aarch64
    perl-ODBM_File-1.16-477.amzn2023.0.6.aarch64
    perl-GDBM_File-debuginfo-1.18-477.amzn2023.0.6.aarch64
    perl-Opcode-1.48-477.amzn2023.0.6.aarch64
    perl-POSIX-1.94-477.amzn2023.0.6.aarch64
    perl-Sys-Hostname-1.23-477.amzn2023.0.6.aarch64
    perl-mro-debuginfo-1.23-477.amzn2023.0.6.aarch64
    perl-ph-5.32.1-477.amzn2023.0.6.aarch64
    perl-I18N-Langinfo-0.19-477.amzn2023.0.6.aarch64
    perl-Fcntl-1.13-477.amzn2023.0.6.aarch64
    perl-debuginfo-5.32.1-477.amzn2023.0.6.aarch64
    perl-libs-debuginfo-5.32.1-477.amzn2023.0.6.aarch64
    perl-ODBM_File-debuginfo-1.16-477.amzn2023.0.6.aarch64
    perl-Fcntl-debuginfo-1.13-477.amzn2023.0.6.aarch64
    perl-File-DosGlob-debuginfo-1.12-477.amzn2023.0.6.aarch64
    perl-Sys-Hostname-debuginfo-1.23-477.amzn2023.0.6.aarch64
    perl-DynaLoader-1.47-477.amzn2023.0.6.aarch64
    perl-interpreter-debuginfo-5.32.1-477.amzn2023.0.6.aarch64
    perl-lib-0.65-477.amzn2023.0.6.aarch64
    perl-Errno-1.30-477.amzn2023.0.6.aarch64
    perl-5.32.1-477.amzn2023.0.6.aarch64

noarch:
    perl-doc-5.32.1-477.amzn2023.0.6.noarch
    perl-I18N-LangTags-0.44-477.amzn2023.0.6.noarch
    perl-Memoize-1.03-477.amzn2023.0.6.noarch
    perl-Unicode-UCD-0.75-477.amzn2023.0.6.noarch
    perl-Math-Complex-1.59-477.amzn2023.0.6.noarch
    perl-debugger-1.56-477.amzn2023.0.6.noarch
    perl-utils-5.32.1-477.amzn2023.0.6.noarch
    perl-ExtUtils-Constant-0.25-477.amzn2023.0.6.noarch
    perl-overload-1.31-477.amzn2023.0.6.noarch
    perl-diagnostics-1.37-477.amzn2023.0.6.noarch
    perl-Tie-File-1.06-477.amzn2023.0.6.noarch
    perl-File-Find-1.37-477.amzn2023.0.6.noarch
    perl-Test-1.31-477.amzn2023.0.6.noarch
    perl-Attribute-Handlers-1.01-477.amzn2023.0.6.noarch
    perl-Benchmark-1.23-477.amzn2023.0.6.noarch
    perl-Pod-Html-1.25-477.amzn2023.0.6.noarch
    perl-Tie-4.6-477.amzn2023.0.6.noarch
    perl-DBM_Filter-0.06-477.amzn2023.0.6.noarch
    perl-Safe-2.41-477.amzn2023.0.6.noarch
    perl-Net-1.02-477.amzn2023.0.6.noarch
    perl-Class-Struct-0.66-477.amzn2023.0.6.noarch
    perl-NEXT-0.67-477.amzn2023.0.6.noarch
    perl-IPC-Open3-1.21-477.amzn2023.0.6.noarch
    perl-SelfLoader-1.26-477.amzn2023.0.6.noarch
    perl-AutoSplit-5.74-477.amzn2023.0.6.noarch
    perl-ExtUtils-Embed-1.35-477.amzn2023.0.6.noarch
    perl-libnetcfg-5.32.1-477.amzn2023.0.6.noarch
    perl-User-pwent-1.03-477.amzn2023.0.6.noarch
    perl-File-Basename-2.85-477.amzn2023.0.6.noarch
    perl-AutoLoader-5.74-477.amzn2023.0.6.noarch
    perl-Dumpvalue-2.27-477.amzn2023.0.6.noarch
    perl-Term-ReadLine-1.17-477.amzn2023.0.6.noarch
    perl-File-Copy-2.34-477.amzn2023.0.6.noarch
    perl-Pod-Functions-1.13-477.amzn2023.0.6.noarch
    perl-Locale-Maketext-Simple-0.21-477.amzn2023.0.6.noarch
    perl-File-stat-1.09-477.amzn2023.0.6.noarch
    perl-base-2.27-477.amzn2023.0.6.noarch
    perl-Thread-3.05-477.amzn2023.0.6.noarch
    perl-fields-2.27-477.amzn2023.0.6.noarch
    perl-Time-1.03-477.amzn2023.0.6.noarch
    perl-open-1.12-477.amzn2023.0.6.noarch
    perl-sigtrap-1.09-477.amzn2023.0.6.noarch
    perl-Getopt-Std-1.12-477.amzn2023.0.6.noarch
    perl-Thread-Semaphore-2.13-477.amzn2023.0.6.noarch
    perl-encoding-warnings-0.13-477.amzn2023.0.6.noarch
    perl-FileHandle-2.03-477.amzn2023.0.6.noarch
    perl-ExtUtils-Miniperl-1.09-477.amzn2023.0.6.noarch
    perl-FileCache-1.10-477.amzn2023.0.6.noarch
    perl-I18N-Collate-1.02-477.amzn2023.0.6.noarch
    perl-Devel-SelfStubber-1.06-477.amzn2023.0.6.noarch
    perl-Symbol-1.08-477.amzn2023.0.6.noarch
    perl-vmsish-1.04-477.amzn2023.0.6.noarch
    perl-deprecate-0.04-477.amzn2023.0.6.noarch
    perl-filetest-1.03-477.amzn2023.0.6.noarch
    perl-locale-1.09-477.amzn2023.0.6.noarch
    perl-FindBin-1.51-477.amzn2023.0.6.noarch
    perl-Tie-Memoize-1.1-477.amzn2023.0.6.noarch
    perl-Term-Complete-1.403-477.amzn2023.0.6.noarch
    perl-autouse-1.11-477.amzn2023.0.6.noarch
    perl-File-Compare-1.100.600-477.amzn2023.0.6.noarch
    perl-if-0.60.800-477.amzn2023.0.6.noarch
    perl-English-1.11-477.amzn2023.0.6.noarch
    perl-Module-Loaded-0.08-477.amzn2023.0.6.noarch
    perl-sort-2.04-477.amzn2023.0.6.noarch
    perl-less-0.03-477.amzn2023.0.6.noarch
    perl-overloading-0.02-477.amzn2023.0.6.noarch
    perl-Search-Dict-1.07-477.amzn2023.0.6.noarch
    perl-macros-5.32.1-477.amzn2023.0.6.noarch
    perl-vars-1.05-477.amzn2023.0.6.noarch
    perl-DirHandle-1.05-477.amzn2023.0.6.noarch
    perl-blib-1.07-477.amzn2023.0.6.noarch
    perl-Text-Abbrev-1.02-477.amzn2023.0.6.noarch
    perl-Config-Extensions-0.03-477.amzn2023.0.6.noarch
    perl-SelectSaver-1.02-477.amzn2023.0.6.noarch
    perl-subs-1.03-477.amzn2023.0.6.noarch
    perl-meta-notation-5.32.1-477.amzn2023.0.6.noarch

src:
    perl-5.32.1-477.amzn2023.0.6.src

x86_64:
    perl-Opcode-debuginfo-1.48-477.amzn2023.0.6.x86_64
    perl-mro-debuginfo-1.23-477.amzn2023.0.6.x86_64
    perl-debugsource-5.32.1-477.amzn2023.0.6.x86_64
    perl-POSIX-1.94-477.amzn2023.0.6.x86_64
    perl-interpreter-5.32.1-477.amzn2023.0.6.x86_64
    perl-Devel-Peek-debuginfo-1.28-477.amzn2023.0.6.x86_64
    perl-ODBM_File-debuginfo-1.16-477.amzn2023.0.6.x86_64
    perl-debuginfo-5.32.1-477.amzn2023.0.6.x86_64
    perl-POSIX-debuginfo-1.94-477.amzn2023.0.6.x86_64
    perl-Time-Piece-1.3401-477.amzn2023.0.6.x86_64
    perl-ph-5.32.1-477.amzn2023.0.6.x86_64
    perl-Hash-Util-debuginfo-0.23-477.amzn2023.0.6.x86_64
    perl-libs-debuginfo-5.32.1-477.amzn2023.0.6.x86_64
    perl-GDBM_File-debuginfo-1.18-477.amzn2023.0.6.x86_64
    perl-Hash-Util-FieldHash-debuginfo-1.20-477.amzn2023.0.6.x86_64
    perl-NDBM_File-debuginfo-1.15-477.amzn2023.0.6.x86_64
    perl-B-1.80-477.amzn2023.0.6.x86_64
    perl-devel-5.32.1-477.amzn2023.0.6.x86_64
    perl-Time-Piece-debuginfo-1.3401-477.amzn2023.0.6.x86_64
    perl-Hash-Util-FieldHash-1.20-477.amzn2023.0.6.x86_64
    perl-IO-debuginfo-1.43-477.amzn2023.0.6.x86_64
    perl-IO-1.43-477.amzn2023.0.6.x86_64
    perl-libs-5.32.1-477.amzn2023.0.6.x86_64
    perl-tests-5.32.1-477.amzn2023.0.6.x86_64
    perl-B-debuginfo-1.80-477.amzn2023.0.6.x86_64
    perl-Hash-Util-0.23-477.amzn2023.0.6.x86_64
    perl-Opcode-1.48-477.amzn2023.0.6.x86_64
    perl-I18N-Langinfo-debuginfo-0.19-477.amzn2023.0.6.x86_64
    perl-Fcntl-debuginfo-1.13-477.amzn2023.0.6.x86_64
    perl-Devel-Peek-1.28-477.amzn2023.0.6.x86_64
    perl-mro-1.23-477.amzn2023.0.6.x86_64
    perl-File-DosGlob-debuginfo-1.12-477.amzn2023.0.6.x86_64
    perl-Sys-Hostname-debuginfo-1.23-477.amzn2023.0.6.x86_64
    perl-DynaLoader-1.47-477.amzn2023.0.6.x86_64
    perl-ODBM_File-1.16-477.amzn2023.0.6.x86_64
    perl-GDBM_File-1.18-477.amzn2023.0.6.x86_64
    perl-I18N-Langinfo-0.19-477.amzn2023.0.6.x86_64
    perl-Fcntl-1.13-477.amzn2023.0.6.x86_64
    perl-NDBM_File-1.15-477.amzn2023.0.6.x86_64
    perl-File-DosGlob-1.12-477.amzn2023.0.6.x86_64
    perl-interpreter-debuginfo-5.32.1-477.amzn2023.0.6.x86_64
    perl-Sys-Hostname-1.23-477.amzn2023.0.6.x86_64
    perl-lib-0.65-477.amzn2023.0.6.x86_64
    perl-Errno-1.30-477.amzn2023.0.6.x86_64
    perl-5.32.1-477.amzn2023.0.6.x86_64

Vulnerable software versions

Amazon Linux AMI: All versions

perl: before 5.32.1-477

CPE2.3 External links

https://alas.aws.amazon.com/AL2023/ALAS-2023-448.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Improper input validation

EUVDB-ID: #VU88575

Risk: High

CVSSv4.0: 8.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]

CVE-ID: CVE-2023-47100

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The vulnerability exists due to improper input validation within the Platform (Perl) component in Oracle Communications Billing and Revenue Management. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.

Mitigation

Update the affected packages:

aarch64:
    perl-Hash-Util-FieldHash-debuginfo-1.20-477.amzn2023.0.6.aarch64
    perl-devel-5.32.1-477.amzn2023.0.6.aarch64
    perl-debugsource-5.32.1-477.amzn2023.0.6.aarch64
    perl-Hash-Util-debuginfo-0.23-477.amzn2023.0.6.aarch64
    perl-Devel-Peek-1.28-477.amzn2023.0.6.aarch64
    perl-B-debuginfo-1.80-477.amzn2023.0.6.aarch64
    perl-NDBM_File-debuginfo-1.15-477.amzn2023.0.6.aarch64
    perl-Devel-Peek-debuginfo-1.28-477.amzn2023.0.6.aarch64
    perl-Time-Piece-debuginfo-1.3401-477.amzn2023.0.6.aarch64
    perl-GDBM_File-1.18-477.amzn2023.0.6.aarch64
    perl-I18N-Langinfo-debuginfo-0.19-477.amzn2023.0.6.aarch64
    perl-IO-1.43-477.amzn2023.0.6.aarch64
    perl-Hash-Util-0.23-477.amzn2023.0.6.aarch64
    perl-POSIX-debuginfo-1.94-477.amzn2023.0.6.aarch64
    perl-IO-debuginfo-1.43-477.amzn2023.0.6.aarch64
    perl-B-1.80-477.amzn2023.0.6.aarch64
    perl-interpreter-5.32.1-477.amzn2023.0.6.aarch64
    perl-Opcode-debuginfo-1.48-477.amzn2023.0.6.aarch64
    perl-File-DosGlob-1.12-477.amzn2023.0.6.aarch64
    perl-Time-Piece-1.3401-477.amzn2023.0.6.aarch64
    perl-mro-1.23-477.amzn2023.0.6.aarch64
    perl-Hash-Util-FieldHash-1.20-477.amzn2023.0.6.aarch64
    perl-tests-5.32.1-477.amzn2023.0.6.aarch64
    perl-libs-5.32.1-477.amzn2023.0.6.aarch64
    perl-NDBM_File-1.15-477.amzn2023.0.6.aarch64
    perl-ODBM_File-1.16-477.amzn2023.0.6.aarch64
    perl-GDBM_File-debuginfo-1.18-477.amzn2023.0.6.aarch64
    perl-Opcode-1.48-477.amzn2023.0.6.aarch64
    perl-POSIX-1.94-477.amzn2023.0.6.aarch64
    perl-Sys-Hostname-1.23-477.amzn2023.0.6.aarch64
    perl-mro-debuginfo-1.23-477.amzn2023.0.6.aarch64
    perl-ph-5.32.1-477.amzn2023.0.6.aarch64
    perl-I18N-Langinfo-0.19-477.amzn2023.0.6.aarch64
    perl-Fcntl-1.13-477.amzn2023.0.6.aarch64
    perl-debuginfo-5.32.1-477.amzn2023.0.6.aarch64
    perl-libs-debuginfo-5.32.1-477.amzn2023.0.6.aarch64
    perl-ODBM_File-debuginfo-1.16-477.amzn2023.0.6.aarch64
    perl-Fcntl-debuginfo-1.13-477.amzn2023.0.6.aarch64
    perl-File-DosGlob-debuginfo-1.12-477.amzn2023.0.6.aarch64
    perl-Sys-Hostname-debuginfo-1.23-477.amzn2023.0.6.aarch64
    perl-DynaLoader-1.47-477.amzn2023.0.6.aarch64
    perl-interpreter-debuginfo-5.32.1-477.amzn2023.0.6.aarch64
    perl-lib-0.65-477.amzn2023.0.6.aarch64
    perl-Errno-1.30-477.amzn2023.0.6.aarch64
    perl-5.32.1-477.amzn2023.0.6.aarch64

noarch:
    perl-doc-5.32.1-477.amzn2023.0.6.noarch
    perl-I18N-LangTags-0.44-477.amzn2023.0.6.noarch
    perl-Memoize-1.03-477.amzn2023.0.6.noarch
    perl-Unicode-UCD-0.75-477.amzn2023.0.6.noarch
    perl-Math-Complex-1.59-477.amzn2023.0.6.noarch
    perl-debugger-1.56-477.amzn2023.0.6.noarch
    perl-utils-5.32.1-477.amzn2023.0.6.noarch
    perl-ExtUtils-Constant-0.25-477.amzn2023.0.6.noarch
    perl-overload-1.31-477.amzn2023.0.6.noarch
    perl-diagnostics-1.37-477.amzn2023.0.6.noarch
    perl-Tie-File-1.06-477.amzn2023.0.6.noarch
    perl-File-Find-1.37-477.amzn2023.0.6.noarch
    perl-Test-1.31-477.amzn2023.0.6.noarch
    perl-Attribute-Handlers-1.01-477.amzn2023.0.6.noarch
    perl-Benchmark-1.23-477.amzn2023.0.6.noarch
    perl-Pod-Html-1.25-477.amzn2023.0.6.noarch
    perl-Tie-4.6-477.amzn2023.0.6.noarch
    perl-DBM_Filter-0.06-477.amzn2023.0.6.noarch
    perl-Safe-2.41-477.amzn2023.0.6.noarch
    perl-Net-1.02-477.amzn2023.0.6.noarch
    perl-Class-Struct-0.66-477.amzn2023.0.6.noarch
    perl-NEXT-0.67-477.amzn2023.0.6.noarch
    perl-IPC-Open3-1.21-477.amzn2023.0.6.noarch
    perl-SelfLoader-1.26-477.amzn2023.0.6.noarch
    perl-AutoSplit-5.74-477.amzn2023.0.6.noarch
    perl-ExtUtils-Embed-1.35-477.amzn2023.0.6.noarch
    perl-libnetcfg-5.32.1-477.amzn2023.0.6.noarch
    perl-User-pwent-1.03-477.amzn2023.0.6.noarch
    perl-File-Basename-2.85-477.amzn2023.0.6.noarch
    perl-AutoLoader-5.74-477.amzn2023.0.6.noarch
    perl-Dumpvalue-2.27-477.amzn2023.0.6.noarch
    perl-Term-ReadLine-1.17-477.amzn2023.0.6.noarch
    perl-File-Copy-2.34-477.amzn2023.0.6.noarch
    perl-Pod-Functions-1.13-477.amzn2023.0.6.noarch
    perl-Locale-Maketext-Simple-0.21-477.amzn2023.0.6.noarch
    perl-File-stat-1.09-477.amzn2023.0.6.noarch
    perl-base-2.27-477.amzn2023.0.6.noarch
    perl-Thread-3.05-477.amzn2023.0.6.noarch
    perl-fields-2.27-477.amzn2023.0.6.noarch
    perl-Time-1.03-477.amzn2023.0.6.noarch
    perl-open-1.12-477.amzn2023.0.6.noarch
    perl-sigtrap-1.09-477.amzn2023.0.6.noarch
    perl-Getopt-Std-1.12-477.amzn2023.0.6.noarch
    perl-Thread-Semaphore-2.13-477.amzn2023.0.6.noarch
    perl-encoding-warnings-0.13-477.amzn2023.0.6.noarch
    perl-FileHandle-2.03-477.amzn2023.0.6.noarch
    perl-ExtUtils-Miniperl-1.09-477.amzn2023.0.6.noarch
    perl-FileCache-1.10-477.amzn2023.0.6.noarch
    perl-I18N-Collate-1.02-477.amzn2023.0.6.noarch
    perl-Devel-SelfStubber-1.06-477.amzn2023.0.6.noarch
    perl-Symbol-1.08-477.amzn2023.0.6.noarch
    perl-vmsish-1.04-477.amzn2023.0.6.noarch
    perl-deprecate-0.04-477.amzn2023.0.6.noarch
    perl-filetest-1.03-477.amzn2023.0.6.noarch
    perl-locale-1.09-477.amzn2023.0.6.noarch
    perl-FindBin-1.51-477.amzn2023.0.6.noarch
    perl-Tie-Memoize-1.1-477.amzn2023.0.6.noarch
    perl-Term-Complete-1.403-477.amzn2023.0.6.noarch
    perl-autouse-1.11-477.amzn2023.0.6.noarch
    perl-File-Compare-1.100.600-477.amzn2023.0.6.noarch
    perl-if-0.60.800-477.amzn2023.0.6.noarch
    perl-English-1.11-477.amzn2023.0.6.noarch
    perl-Module-Loaded-0.08-477.amzn2023.0.6.noarch
    perl-sort-2.04-477.amzn2023.0.6.noarch
    perl-less-0.03-477.amzn2023.0.6.noarch
    perl-overloading-0.02-477.amzn2023.0.6.noarch
    perl-Search-Dict-1.07-477.amzn2023.0.6.noarch
    perl-macros-5.32.1-477.amzn2023.0.6.noarch
    perl-vars-1.05-477.amzn2023.0.6.noarch
    perl-DirHandle-1.05-477.amzn2023.0.6.noarch
    perl-blib-1.07-477.amzn2023.0.6.noarch
    perl-Text-Abbrev-1.02-477.amzn2023.0.6.noarch
    perl-Config-Extensions-0.03-477.amzn2023.0.6.noarch
    perl-SelectSaver-1.02-477.amzn2023.0.6.noarch
    perl-subs-1.03-477.amzn2023.0.6.noarch
    perl-meta-notation-5.32.1-477.amzn2023.0.6.noarch

src:
    perl-5.32.1-477.amzn2023.0.6.src

x86_64:
    perl-Opcode-debuginfo-1.48-477.amzn2023.0.6.x86_64
    perl-mro-debuginfo-1.23-477.amzn2023.0.6.x86_64
    perl-debugsource-5.32.1-477.amzn2023.0.6.x86_64
    perl-POSIX-1.94-477.amzn2023.0.6.x86_64
    perl-interpreter-5.32.1-477.amzn2023.0.6.x86_64
    perl-Devel-Peek-debuginfo-1.28-477.amzn2023.0.6.x86_64
    perl-ODBM_File-debuginfo-1.16-477.amzn2023.0.6.x86_64
    perl-debuginfo-5.32.1-477.amzn2023.0.6.x86_64
    perl-POSIX-debuginfo-1.94-477.amzn2023.0.6.x86_64
    perl-Time-Piece-1.3401-477.amzn2023.0.6.x86_64
    perl-ph-5.32.1-477.amzn2023.0.6.x86_64
    perl-Hash-Util-debuginfo-0.23-477.amzn2023.0.6.x86_64
    perl-libs-debuginfo-5.32.1-477.amzn2023.0.6.x86_64
    perl-GDBM_File-debuginfo-1.18-477.amzn2023.0.6.x86_64
    perl-Hash-Util-FieldHash-debuginfo-1.20-477.amzn2023.0.6.x86_64
    perl-NDBM_File-debuginfo-1.15-477.amzn2023.0.6.x86_64
    perl-B-1.80-477.amzn2023.0.6.x86_64
    perl-devel-5.32.1-477.amzn2023.0.6.x86_64
    perl-Time-Piece-debuginfo-1.3401-477.amzn2023.0.6.x86_64
    perl-Hash-Util-FieldHash-1.20-477.amzn2023.0.6.x86_64
    perl-IO-debuginfo-1.43-477.amzn2023.0.6.x86_64
    perl-IO-1.43-477.amzn2023.0.6.x86_64
    perl-libs-5.32.1-477.amzn2023.0.6.x86_64
    perl-tests-5.32.1-477.amzn2023.0.6.x86_64
    perl-B-debuginfo-1.80-477.amzn2023.0.6.x86_64
    perl-Hash-Util-0.23-477.amzn2023.0.6.x86_64
    perl-Opcode-1.48-477.amzn2023.0.6.x86_64
    perl-I18N-Langinfo-debuginfo-0.19-477.amzn2023.0.6.x86_64
    perl-Fcntl-debuginfo-1.13-477.amzn2023.0.6.x86_64
    perl-Devel-Peek-1.28-477.amzn2023.0.6.x86_64
    perl-mro-1.23-477.amzn2023.0.6.x86_64
    perl-File-DosGlob-debuginfo-1.12-477.amzn2023.0.6.x86_64
    perl-Sys-Hostname-debuginfo-1.23-477.amzn2023.0.6.x86_64
    perl-DynaLoader-1.47-477.amzn2023.0.6.x86_64
    perl-ODBM_File-1.16-477.amzn2023.0.6.x86_64
    perl-GDBM_File-1.18-477.amzn2023.0.6.x86_64
    perl-I18N-Langinfo-0.19-477.amzn2023.0.6.x86_64
    perl-Fcntl-1.13-477.amzn2023.0.6.x86_64
    perl-NDBM_File-1.15-477.amzn2023.0.6.x86_64
    perl-File-DosGlob-1.12-477.amzn2023.0.6.x86_64
    perl-interpreter-debuginfo-5.32.1-477.amzn2023.0.6.x86_64
    perl-Sys-Hostname-1.23-477.amzn2023.0.6.x86_64
    perl-lib-0.65-477.amzn2023.0.6.x86_64
    perl-Errno-1.30-477.amzn2023.0.6.x86_64
    perl-5.32.1-477.amzn2023.0.6.x86_64

Vulnerable software versions

Amazon Linux AMI: All versions

perl: before 5.32.1-477

CPE2.3 External links

https://alas.aws.amazon.com/AL2023/ALAS-2023-448.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###