Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-2277

Опубликовано: 17 окт. 2017
Источник: nvd
CVSS3: 7.1
CVSS2: 3.6
EPSS Низкий

Описание

The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive information or write to arbitrary files via a symlink attack, related to use of the tmpnam function.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:perltidy_project:perltidy:*:*:*:*:*:*:*:*
Версия до 2012-07-01-1 (включая)

EPSS

Процентиль: 19%
0.0006
Низкий

7.1 High

CVSS3

3.6 Low

CVSS2

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 7.1
ubuntu
больше 8 лет назад

The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive information or write to arbitrary files via a symlink attack, related to use of the tmpnam function.

redhat
почти 12 лет назад

The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive information or write to arbitrary files via a symlink attack, related to use of the tmpnam function.

CVSS3: 7.1
debian
больше 8 лет назад

The make_temporary_filename function in perltidy 20120701-1 and earlie ...

CVSS3: 7.1
github
больше 3 лет назад

The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive information or write to arbitrary files via a symlink attack, related to use of the tmpnam function.

EPSS

Процентиль: 19%
0.0006
Низкий

7.1 High

CVSS3

3.6 Low

CVSS2

Дефекты

CWE-284