StrawberryPerl/Perl-Dist-Strawberry

Strawberry Perl vulnerability in v5.32.x.x corrected?

Closed this issue · 1 comments

There was a vulnerability listed for Strawberry Perl v5.32.x.x at https://nvd.nist.gov/vuln/detail/CVE-2022-36564#. Could anyone please tell us if this issue has been fixed for v 5.38.2.2? Thank you.

CVE-2022-36564 Detail
Incorrect access control in the install directory (C:\Strawberry) of Strawberry Perl v5.32.1.1 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory.

Duplicate of #126