|
|
| |
|
| |
perl-Config-IniFiles: insecure temporary files
| Package(s): | perl-Config-IniFiles |
CVE #(s): | CVE-2012-2451
|
| Created: | May 22, 2012 |
Updated: | August 21, 2012 |
| Description: |
From the Red Hat bugzilla:
perl-Config-IniFiles used a predictable temporary file name (${filename}-new) which makes it prone to a symlink attack. If a malicious user were to create a symlink pointing to another file writable by the user running an application that used perl-Config-IniFiles, they could overwrite the contents of that file. |
| Alerts: |
|
( Log in to post comments)
|
|
|