Candidate: CVE-2017-0374 PublicDate: 2017-05-23 18:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0374 https://anonscm.debian.org/cgit/pkg-perl/packages/libconfig-model-perl.git/commit/?h=stretch&id=0de8471e5a8958ad37446dfcd0362a269e3ec573 Description: lib/Config/Model.pm in Config-Model (aka libconfig-model-perl) before 2.102 allows local users to gain privileges via a crafted model in the current working directory, related to use of . with the INC array. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_libconfig-model-perl: distro: https://anonscm.debian.org/cgit/pkg-perl/packages/libconfig-model-perl.git/commit/?h=stretch&id=0de8471e5a8958ad37446dfcd0362a269e3ec573 upstream_libconfig-model-perl: released (2.097-2) precise/esm_libconfig-model-perl: DNE trusty_libconfig-model-perl: ignored (reached end-of-life) trusty/esm_libconfig-model-perl: DNE (trusty was needed) vivid/stable-phone-overlay_libconfig-model-perl: DNE vivid/ubuntu-core_libconfig-model-perl: DNE xenial_libconfig-model-perl: ignored (end of standard support, was needed) yakkety_libconfig-model-perl: ignored (reached end-of-life) zesty_libconfig-model-perl: ignored (reached end-of-life) artful_libconfig-model-perl: not-affected (2.097-2) bionic_libconfig-model-perl: not-affected (2.097-2) cosmic_libconfig-model-perl: not-affected (2.097-2) disco_libconfig-model-perl: not-affected (2.097-2) eoan_libconfig-model-perl: not-affected (2.097-2) focal_libconfig-model-perl: not-affected (2.097-2) groovy_libconfig-model-perl: not-affected (2.097-2) hirsute_libconfig-model-perl: not-affected (2.097-2) impish_libconfig-model-perl: not-affected (2.097-2) jammy_libconfig-model-perl: not-affected (2.097-2) devel_libconfig-model-perl: not-affected (2.097-2)