LWN.net Logo

perl-Config-IniFiles: insecure temporary files

Package(s):perl-Config-IniFiles CVE #(s):CVE-2012-2451
Created:May 22, 2012 Updated:August 21, 2012
Description: From the Red Hat bugzilla:

perl-Config-IniFiles used a predictable temporary file name (${filename}-new) which makes it prone to a symlink attack. If a malicious user were to create a symlink pointing to another file writable by the user running an application that used perl-Config-IniFiles, they could overwrite the contents of that file.

Alerts:
Fedora FEDORA-2012-7777 2012-05-22
Fedora FEDORA-2012-7802 2012-05-22
Mageia MGASA-2012-0127 2012-06-27
Gentoo 201208-05 2012-08-14
Ubuntu USN-1543-1 2012-08-20

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds