CVE-2021-36770 - CVE House
Back to Database
Status published High CVE-2021-36770

Encode.pm, as distributed in Perl through 5.34.0, allows local users...

Vulnerability Description

Encode.pm, as distributed in Perl through 5.34.0, allows local users to gain privileges via a Trojan horse Encode::ConfigLocal library (in the current working directory) that preempts dynamic module loading. Exploitation requires an unusual configuration, and certain 2021 versions of Encode.pm (3.05 through 3.11). This issue occurs because the || operator evaluates @INC in a scalar context, and thus @INC has only an integer value.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-36770

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

p5-encode project

View all reports →

Affected Software

p5-encode, fedora
Vulnerable Versions:
3.05, 34, 33

Timeline

Official Publish: August 11th, 2021
Last Modified: November 3rd, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.