Candidate: CVE-2017-0373 PublicDate: 2017-05-23 18:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0373 https://anonscm.debian.org/cgit/pkg-perl/packages/libconfig-model-perl.git/commit/?h=stretch&id=e7e5dd1a650939a0e021d1d5b311dbb3c4884773 Description: The gen_class_pod implementation in lib/Config/Model/Utils/GenClassPod.pm in Config-Model (aka libconfig-model-perl) before 2.102 has a dangerous "use lib" line, which allows remote attackers to have an unspecified impact via a crafted Debian package file. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H [7.3 HIGH] Patches_libconfig-model-perl: distro: https://anonscm.debian.org/cgit/pkg-perl/packages/libconfig-model-perl.git/commit/?h=stretch&id=e7e5dd1a650939a0e021d1d5b311dbb3c4884773 upstream_libconfig-model-perl: released (2.097-2) precise/esm_libconfig-model-perl: DNE trusty_libconfig-model-perl: ignored (reached end-of-life) trusty/esm_libconfig-model-perl: DNE (trusty was needed) vivid/stable-phone-overlay_libconfig-model-perl: DNE vivid/ubuntu-core_libconfig-model-perl: DNE xenial_libconfig-model-perl: ignored (end of standard support, was needed) yakkety_libconfig-model-perl: ignored (reached end-of-life) zesty_libconfig-model-perl: ignored (reached end-of-life) artful_libconfig-model-perl: not-affected (2.097-2) bionic_libconfig-model-perl: not-affected (2.097-2) cosmic_libconfig-model-perl: not-affected (2.097-2) disco_libconfig-model-perl: not-affected (2.097-2) eoan_libconfig-model-perl: not-affected (2.097-2) focal_libconfig-model-perl: not-affected (2.097-2) groovy_libconfig-model-perl: not-affected (2.097-2) hirsute_libconfig-model-perl: not-affected (2.097-2) impish_libconfig-model-perl: not-affected (2.097-2) jammy_libconfig-model-perl: not-affected (2.097-2) devel_libconfig-model-perl: not-affected (2.097-2)