PT-2017-7889 · Unknown+1 · Check-All-The-Things+2

Jakub Wilk

+1

·

Publicado

2017-05-17

·

Atualizado

2020-03-02

·

CVE-2016-10374

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions perltidy versions prior to 20160302 perlcritic (affected versions not specified) check-all-the-things (affected versions not specified)
Description The issue allows local users to overwrite arbitrary files by creating a symlink. This can be demonstrated by creating a perltidy.ERR symlink that the victim cannot delete. The problem arises because perltidy relies on the current working directory for certain output files and lacks a symlink-attack protection mechanism.
Recommendations For perltidy versions prior to 20160302, consider updating to a version that includes a symlink-attack protection mechanism. For perlcritic, check-all-the-things, and other affected software, restrict access to the vulnerable perltidy component until a patch is available. As a temporary workaround, consider disabling the use of perltidy for output files that rely on the current working directory until a patch is available.

Correção

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-10374
MGASA-2017-0301

Produtos afetados

Check-All-The-Things
Perlcritic
Perltidy