YAML Vulnerability in Perl Allows Arbitrary Code Execution in Affected Versions
CVE-2019-25777
Currently unrated
What is CVE-2019-25777?
The vulnerability in YAML versions prior to 1.27_001 for Perl allows a crafted perl/glob document to replace any package variable, potentially leading to arbitrary code execution. This risk arises when the document specifies package names and symbols without restrictions, enabling the attacker to manipulate the loaded environment. If an attacker combines documents to invoke code loading, this can result in the execution of unintended Perl code, making it crucial for users to upgrade to the latest patched versions to mitigate potential threats.
