|
|
| |
|
| |
perl: insecure temp file creation
| Package(s): | perl |
CVE #(s): | CAN-2004-0976
|
| Created: | November 2, 2004 |
Updated: | December 7, 2004 |
| Description: |
Trustix Secure Linux has discovered some vulnerabilities in the perl
package. The utility "instmodsh", the Perl package "PPPort.pm", and several
test scripts (which are not shipped and only used during build) created
temporary files in an insecure way, which could allow a symlink attack to
create or overwrite arbitrary files with the privileges of the user
invoking the program, or building the perl package, respectively. |
| Alerts: |
|
( Log in to post comments)
|
|
|