LWN.net Logo

perl-PAR: insecure temporary file handling

Package(s):perl-PAR perl-PAR-Packer CVE #(s):CVE-2011-4114
Created:December 21, 2011 Updated:December 21, 2011
Description: From the Red Hat bugzilla entry: It was reported that PAR::Packer's par_mktmpdir() function would create /tmp/par-[username] directories insecurely, which could allow a local attacker to make changes to the cache directory and possibly the PAR-packged program. PAR::Packer does not verify that the user owns the directory, nor does it create it with secure permissions.
Alerts:
Fedora FEDORA-2011-16856 2011-12-10
Fedora FEDORA-2011-16859 2011-12-10
Fedora FEDORA-2011-16856 2011-12-10
Fedora FEDORA-2011-16859 2011-12-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds