PT-2006-2295 · Unknown · Cgi::Session

Joey Hess

·

Published

2006-03-19

·

Updated

2017-07-20

·

CVE-2006-1279

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions CGI::Session version 4.03-1
Description The issue allows local users to overwrite arbitrary files via a symlink attack on temporary files used by certain drivers. This can be achieved through drivers such as Driver::File, Driver::db file, and possibly Driver::sqlite.
Recommendations For CGI::Session version 4.03-1, consider updating to a newer version that addresses this issue, as no specific workaround is provided for this version. As a temporary mitigation measure, restrict access to temporary files used by the affected drivers to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1279

Affected Products

Cgi::Session