The VDir::MapPathA and VDir::MapPathW functions in Perl 5.22 allow remote attackers to cause a denial of service (out-of-bounds read) and possibly execute arbitrary code via a crafted (1) drive letter or (2) pInName argument. Reference: https://rt.perl.org/Public/Bug/Display.html?id=126755
Upstream commit: https://github.com/Perl/perl5/commit/52236464559c6e410a4587d3c6da9639e75f3ec1#diff-31982a731a0996d0cc82a4ad4e70ad50
This is a Microsoft Windows only flaw in perl as mentioned in the original report at: https://github.com/Perl/perl5/issues/15067#issuecomment-544077033
Statement: This is a Microsoft Windows only flaw in perl as mentioned in the original report at: https://github.com/Perl/perl5/issues/15067#issuecomment-544077033