Enable "." to be removed from @INC in /etc/perl/sitecustomize.pl
See CVE-2016-1238. The known vulnerable modules have been fixed, but this should eliminate also currently unknown similar vulnerabilities if a user chooses to uncomment the line in this file. This facility is expected to be removed after the Debian stretch release, at which point "." will be removed at compile time and sitecustomize.pl will no longer have any effect. Note that this setup leaves systems with just perl-base installed potentially vulnerable. This is currently considered an acceptable tradeoff. Based on work done for jessie by Niko Tyni, adapted for sid by Dominic Hargreaves.
Loading
Please register or sign in to comment