← Vulnerability feed

Vulnerability record · CVE-2011-1487 · published 11 April 2011

CVE-2011-1487: Perl permissions and access controls vulnerability

Perl · Perl

The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

5.0 CVSS 2.0 Medium EPSS 11% · top 4.4% CWE-264 · Permissions and access controls
5.0CVSS 2.0 base score
11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
30References, 10 tagged exploit
16 Jun 2026Last modified by NVD

Description

The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

AV:N/AC:L/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057891.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057971.html
http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html
http://openwall.com/lists/oss-security/2011/04/01/3 ExploitPatch
http://openwall.com/lists/oss-security/2011/04/04/35 ExploitPatch
http://perl5.git.perl.org/perl.git/commit/539689e74a3bcb04d29e4cd9396de91a81045b99 Patch
http://rt.perl.org/rt3/Public/Bug/Display.html?id=87336 Exploit
http://secunia.com/advisories/43921 Vendor Advisory
http://secunia.com/advisories/44168
http://www.debian.org/security/2011/dsa-2265
http://www.mandriva.com/security/advisories?name=MDVSA-2011:091
http://www.securityfocus.com/bid/47124 Exploit
https://bugzilla.redhat.com/show_bug.cgi?id=692844
https://bugzilla.redhat.com/show_bug.cgi?id=692898 ExploitPatch
https://exchange.xforce.ibmcloud.com/vulnerabilities/66528
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057891.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057971.html
http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html
http://openwall.com/lists/oss-security/2011/04/01/3 ExploitPatch
http://openwall.com/lists/oss-security/2011/04/04/35 ExploitPatch
http://perl5.git.perl.org/perl.git/commit/539689e74a3bcb04d29e4cd9396de91a81045b99 Patch
http://rt.perl.org/rt3/Public/Bug/Display.html?id=87336 Exploit
http://secunia.com/advisories/43921 Vendor Advisory
http://secunia.com/advisories/44168
http://www.debian.org/security/2011/dsa-2265
http://www.mandriva.com/security/advisories?name=MDVSA-2011:091
http://www.securityfocus.com/bid/47124 Exploit
https://bugzilla.redhat.com/show_bug.cgi?id=692844
https://bugzilla.redhat.com/show_bug.cgi?id=692898 ExploitPatch
https://exchange.xforce.ibmcloud.com/vulnerabilities/66528

Track CVE-2011-1487 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-8376Perl vulnerabilityPerl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular express…EPSS 0.48%9.8CVE-2026-4176Perl vulnerabilityPerl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Z…EPSS 0.81%9.8CVE-2022-48522Perl out-of-bounds write vulnerabilityIn Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalation.EPSS 2.6%9.8CVE-2018-18311Perl integer overflow vulnerabilityPerl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.EPSS 12%9.8CVE-2018-18314Perl memory buffer overflow vulnerabilityPerl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations.EPSS 6.1%9.8CVE-2018-18312Perl memory buffer overflow vulnerabilityPerl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.EPSS 12%9.8CVE-2018-6797Debian linux out-of-bounds write vulnerabilityAn issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes w…EPSS 6.5%9.8CVE-2018-6913Debian linux out-of-bounds write vulnerabilityHeap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbitrary code via a large item c…EPSS 11%

Source: NIST National Vulnerability Database (record CVE-2011-1487), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.