PT-2012-4054 · Perl · Config::Inifiles
Vincent Danen
·
Publicado
2012-06-27
·
Atualizado
2024-06-15
·
CVE-2012-2451
CVSS v2.0
3.6
Baixa
| Vetor | AV:L/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Config::IniFiles versions prior to 2.71
Description
The issue allows local users to potentially overwrite arbitrary files via a symlink attack due to the creation of temporary files with predictable names. It has been reported that this might only be exploitable by writing in the same directory as the .ini file, which could limit the ability to cross privilege boundaries.
Recommendations
For versions prior to 2.71, consider updating to version 2.71 or later to resolve the issue. As a temporary workaround, restrict write access to the directory containing the .ini file to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Config::Inifiles