CPANSA-File-Path-2004-0452: File-Path vulnerability

Publisher giterlizzi Document category csaf_security_advisory
Initial release date 2004-12-21T00:00:00 Engine CSAF Perl Toolkit 0.25
Current release date 2004-12-21T00:00:00 Build Date
Current version 1 Status final
CVSS v3.1 Base Score Severity
Original language Language en
Also referred to

Vulnerability Description

Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for the world, which allows local users to delete arbitrary files and directories, and possibly read files and directories, via a symlink attack.

Vulnerabilities

CVE-2004-0452

Vulnerability Description

Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for the world, which allows local users to delete arbitrary files and directories, and possibly read files and directories, via a symlink attack.

Product status

Known affected
Product Score
File-Path greater than or equal 1.06 and less than or equal 1.404
CVSS Version CVSS Vector CVSS Base Score CVSS Base Severity
2.0 AV:L/AC:H/Au:N/C:N/I:P/A:P 2.6 Low

giterlizzi

Namespace: https://github.com/giterlizzi/

gdt@cpan.org

References

Revision history

Version Date of the revision Summary of the revision
1 Tue Dec 21 00:00:00 2004 First release

Sharing rules

TLP:WHITE
For the TLP version see: https://www.first.org/tlp/