Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.1
CVE-2023-31486: rootio-perl: Unauthorized access to sensitive data
CVE-2023-31486 · published 26 days ago
Summary
The rootio-perl package, used in Root:Debian:12, had a security issue that allowed unauthorized access to sensitive data. Root has released a patch to fix this issue, and you should update your package to a fixed version to prevent any potential problems.
What to do
- Update debian rootio-perl to version 5.36.0-7+deb12u2.root.io.5.
- Update debian rootio-libhttp-tiny-perl to version 0.082-2.root.io.1.
- Update debian rootio-perl to version 5.36.0-7+deb12u3.root.io.8.
- Update debian rootio-perl to version 5.36.0-7+deb12u3.root.io.12.
- Update debian libhttp-tiny-perl to version 0.088-1.
- Update debian perl to version 5.38.2-2.
- Update debian rootio-perl to version 5.36.0-7+deb12u3.root.io.9.
- Update debian rootio-perl to version 5.36.0-7+deb12u3.root.io.10.
- Update debian perl to version 5.36.0-7+deb12u3.root.io.12.
- Update debian libhttp-tiny-perl to version 0.082-2.root.io.1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Root:Debian:12 | debian | rootio-perl |
< 5.36.0-7+deb12u2.root.io.5 < 5.36.0-7+deb12u3.root.io.8 < 5.36.0-7+deb12u3.root.io.12 < 5.36.0-7+deb12u3.root.io.9 < 5.36.0-7+deb12u3.root.io.10 Fix: upgrade to 5.36.0-7+deb12u2.root.io.5
|
| Root:Debian:12 | debian | rootio-libhttp-tiny-perl |
< 0.082-2.root.io.1 Fix: upgrade to 0.082-2.root.io.1
|
| Ubuntu:Pro:14.04:LTS | canonical | perl | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | perl | All versions |
| Ubuntu:18.04:LTS | canonical | perl | All versions |
| Ubuntu:16.04:LTS | canonical | libhttp-tiny-perl | All versions |
| Ubuntu:18.04:LTS | canonical | libhttp-tiny-perl | All versions |
| Ubuntu:20.04:LTS | canonical | perl | All versions |
| Ubuntu:20.04:LTS | canonical | libhttp-tiny-perl | All versions |
| Ubuntu:22.04:LTS | canonical | libhttp-tiny-perl | All versions |
| Ubuntu:22.04:LTS | canonical | perl | All versions |
| Debian:12 | debian | libhttp-tiny-perl | All versions |
| Debian:13 | debian | libhttp-tiny-perl |
< 0.088-1 Fix: upgrade to 0.088-1
|
| Debian:14 | debian | libhttp-tiny-perl |
< 0.088-1 Fix: upgrade to 0.088-1
|
| Debian:12 | debian | perl | All versions |
| Debian:13 | debian | perl |
< 5.38.2-2 Fix: upgrade to 5.38.2-2
|
| Debian:14 | debian | perl |
< 5.38.2-2 Fix: upgrade to 5.38.2-2
|
| Root:Debian:12 | debian | perl |
< 5.36.0-7+deb12u3.root.io.12 Fix: upgrade to 5.36.0-7+deb12u3.root.io.12
|
| Root:Debian:12 | debian | libhttp-tiny-perl |
< 0.082-2.root.io.1 Fix: upgrade to 0.082-2.root.io.1
|
Original advisory text
CVE-2023-31486 in perl - Patched by Root
Root has patched CVE-2023-31486 in the perl package for Root:Debian:12. Multiple fixed versions available.
References
- https://github.com/chansen/p5-http-tiny/issues/134 Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/05/03/3 Third Party Advisory
- https://www.reddit.com/r/perl/comments/111tadi/psa_httptiny_disabled_ssl_verific... Third Party Advisory
- https://www.openwall.com/lists/oss-security/2023/05/03/4 Third Party Advisory
- https://www.openwall.com/lists/oss-security/2023/04/18/14 Third Party Advisory
- https://hackeriet.github.io/cpan-http-tiny-overview/ Third Party Advisory
- https://ubuntu.com/security/CVE-2023-31486 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2023-31486 Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2023-31486 Vendor Advisory
- http://www.openwall.com/lists/oss-security/2023/05/03/5 Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/04/29/1 Third Party Advisory
- https://blog.hackeriet.no/perl-http-tiny-insecure-tls-default-affects-cpan-modul... Third Party Advisory
Severity
8.1
High
CVSS 3.1: 8.1 (OSV)
Exploitation
EPSS 2%
Timeline
Published9 Aug 2026
Updated2 Sep 2026
First seen1 Jun 2026
Monitor software like this
Free during beta