PT-2012-4054 · Perl · Config::Inifiles

Vincent Danen

·

Publicado

2012-06-27

·

Atualizado

2024-06-15

·

CVE-2012-2451

CVSS v2.0

3.6

Baixa

VetorAV:L/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Config::IniFiles versions prior to 2.71
Description The issue allows local users to potentially overwrite arbitrary files via a symlink attack due to the creation of temporary files with predictable names. It has been reported that this might only be exploitable by writing in the same directory as the .ini file, which could limit the ability to cross privilege boundaries.
Recommendations For versions prior to 2.71, consider updating to version 2.71 or later to resolve the issue. As a temporary workaround, restrict write access to the directory containing the .ini file to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2012-2451
OPENSUSE-SU-2024:10146-1

Produtos afetados

Config::Inifiles