CVE-2015-8608: Perl

Critical severity, CVSS 9.8. EPSS: 4.6% chance of exploitation in the next 30 days.

The VDir::MapPathA and VDir::MapPathW functions in Perl 5.22 allow remote attackers to cause a denial of service (out-of-bounds read) and possibly execute arbitrary code via a crafted (1) drive letter or (2) pInName argument.

Affected products

  • Perl Perl: version 5.22 only

Published 2017-02-07. Last modified 2026-06-17.