Back

CVE-2005-4278

Untrusted search path vulnerability in Perl before 5.8.7-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.

Published: Dec 16, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (17)

Vendor Product Version
larry_wall perl *
larry_wall perl 5.3
larry_wall perl 5.4
larry_wall perl 5.4.5
larry_wall perl 5.5
larry_wall perl 5.5.3
larry_wall perl 5.6.1
larry_wall perl 5.8.0
larry_wall perl 5.8.1
larry_wall perl 5.8.3
larry_wall perl 5.8.4
larry_wall perl 5.8.4.1
larry_wall perl 5.8.4.2
larry_wall perl 5.8.4.2.3
larry_wall perl 5.8.4.3
larry_wall perl 5.8.4.4
larry_wall perl 5.8.4.5

GitHub Security Advisory GHSA-f2ph-fm4w-vfqw

Untrusted search path vulnerability in Perl before 5.8.7-r1 on Gentoo Linux allows local users in...

Risk Scores

CVSS Score 7.2 / 10
EPSS Score 0.40%

Top 67% most likely to be exploited

Threat Score 28.9 / 100

Data Sources

NVD EPSS GitHub