|
|
| |
|
| |
perl-PAR: insecure temporary file handling
| Package(s): | perl-PAR perl-PAR-Packer |
CVE #(s): | CVE-2011-4114
|
| Created: | December 21, 2011 |
Updated: | December 21, 2011 |
| Description: |
From the Red Hat bugzilla entry: It was reported that PAR::Packer's par_mktmpdir() function would create
/tmp/par-[username] directories insecurely, which could allow a local attacker
to make changes to the cache directory and possibly the PAR-packged program.
PAR::Packer does not verify that the user owns the directory, nor does it
create it with secure permissions. |
| Alerts: |
|
( Log in to post comments)
|
|
|