K 10 svn:author V 7 matthew K 8 svn:date V 27 2016-08-12T10:56:12.264754Z K 7 svn:log V 388 The perl5 release candidate versions also address the XSLoader local arbitrary code execution vulnerability (CVE-2016-6185), as documented in perldelta(1) So perl5.22-5.22.3.r2 and perl5.24-5.24.1.r2 are not vulnerable. I can't confirm if the updates to perl5.18 and perl5.20 also solve the XSLoader bug or not but by inspection of the source code, I don't believe that to be the case. END