Vulnerability Description
Linux::Statm::Tiny for Perl before 0.0701 allows untrusted code from the current working directory ('.') to be loaded similar to CVE-2016-1238. If an attacker can place a malicious file in current working directory, it may be loaded instead of the intended file, potentially leading to arbitrary code execution. Linux::Statm::Tiny uses Mite to produce the affected code section due to CVE-2025-30672
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://blogs.perl.org/users/todd_rinaldo/2016/11/what-happened-to-dot-in-inc.ht
- https://metacpan.org/release/RRWO/Linux-Statm-Tiny-0.0700/source/lib/Linux/Statm
- https://metacpan.org/release/RRWO/Linux-Statm-Tiny-0.0701/changes
FAQ
What is CVE-2025-3051?
CVE-2025-3051 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Linux::Statm::Tiny for Perl before 0.0701 allows untrusted code from the current working directory ('.') to be loaded similar to CVE-2016-1238. If an attacker can place a malicious file in current wo...
How severe is CVE-2025-3051?
CVE-2025-3051 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-3051?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.