CVE-2022-48522
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Aug 22, 2023
Updated: Sep 15, 2023
CWE ID 787
Summary
CVE-2022-48522 is a newly disclosed vulnerability affecting Perl 5.34.0. This issue lies in the sv.c file within the function S_find_uninit_var. An attacker can exploit this stack-based crash, resulting in remote code execution or local privilege escalation. The crash occurs due to an uninitialized variable, presenting a significant security risk. Perl users are strongly encouraged to apply the available patch as soon as possible to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Perl
Affected Vendors
- Perl