PT-2006-2295 · Unknown · Cgi::Session
Joey Hess
·
Published
2006-03-19
·
Updated
2017-07-20
·
CVE-2006-1279
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CGI::Session version 4.03-1
Description
The issue allows local users to overwrite arbitrary files via a symlink attack on temporary files used by certain drivers. This can be achieved through drivers such as Driver::File, Driver::db file, and possibly Driver::sqlite.
Recommendations
For CGI::Session version 4.03-1, consider updating to a newer version that addresses this issue, as no specific workaround is provided for this version. As a temporary mitigation measure, restrict access to temporary files used by the affected drivers to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cgi::Session