Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gxwf-286g-rc8g

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The par_mktmpdir function in the PAR::Packer module before 1.012 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program. NOTE: a similar vulnerability was reported for PAR, but this has been assigned a different CVE identifier.

The par_mktmpdir function in the PAR::Packer module before 1.012 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program. NOTE: a similar vulnerability was reported for PAR, but this has been assigned a different CVE identifier.

EPSS

Процентиль: 24%
0.00082
Низкий

Связанные уязвимости

ubuntu
около 14 лет назад

The par_mktmpdir function in the PAR::Packer module before 1.012 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program. NOTE: a similar vulnerability was reported for PAR, but this has been assigned a different CVE identifier.

nvd
около 14 лет назад

The par_mktmpdir function in the PAR::Packer module before 1.012 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program. NOTE: a similar vulnerability was reported for PAR, but this has been assigned a different CVE identifier.

debian
около 14 лет назад

The par_mktmpdir function in the PAR::Packer module before 1.012 for P ...

EPSS

Процентиль: 24%
0.00082
Низкий