{"id":"AZL-89283","summary":"CVE-2025-15649 affecting package perl for versions less than 5.38.2-512","details":"IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.\n\n_dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.\n\nThe exception propagates out of IO::Uncompress::Unzip-\u003enew($file) where callers expect undef plus $UnzipError.","modified":"2026-08-30T05:26:50Z","published":"2026-05-27T04:16:23Z","upstream":["CVE-2025-15649"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-15649"}],"affected":[{"package":{"name":"perl","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/perl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.38.2-512"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-89283.json"}}],"schema_version":"1.9.0"}