The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.
| Software | From | Fixed in |
|---|---|---|
| canonical / ubuntu_linux | 15.10 | 15.10.x |
| canonical / ubuntu_linux | 15.04 | 15.04.x |
| perl / pathtools | - | 3.61.x |
| debian / debian_linux | 8.0 | 8.0.x |