PT-2012-4054 · Perl · Config::Inifiles
Vincent Danen
·
Published
2012-06-27
·
Updated
2024-06-15
·
CVE-2012-2451
CVSS v2.0
3.6
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Config::IniFiles versions prior to 2.71
Description
The issue allows local users to potentially overwrite arbitrary files via a symlink attack due to the creation of temporary files with predictable names. It has been reported that this might only be exploitable by writing in the same directory as the .ini file, which could limit the ability to cross privilege boundaries.
Recommendations
For versions prior to 2.71, consider updating to version 2.71 or later to resolve the issue. As a temporary workaround, restrict write access to the directory containing the .ini file to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Config::Inifiles