Local privilege escalation in Perl's Encode module affecting multiple versions
CVE-2021-36770
What is CVE-2021-36770?
The Encode.pm module, included with Perl distributions from version 5.34.0, presents a security risk that allows local users to escalate their privileges. This vulnerability arises due to the loading of a malicious Encode::ConfigLocal library from the current working directory, circumventing dynamic module loading. This exploit relies on specific configurations and affects certain versions of Encode.pm (3.05–3.11). A critical flaw occurs because the || operator processes @INC in a scalar context, reducing its intended functionality to an integer value.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
