Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-2277

Опубликовано: 03 мар. 2014
Источник: redhat
CVSS2: 2.1
EPSS Низкий

Описание

The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive information or write to arbitrary files via a symlink attack, related to use of the tmpnam function.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6perltidyWill not fix
Red Hat Enterprise Linux 7perltidyNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-378
https://bugzilla.redhat.com/show_bug.cgi?id=1074720perltidy: insecure temporary file creation

EPSS

Процентиль: 28%
0.00354
Низкий

2.1 Low

CVSS2

Связанные уязвимости

CVSS3: 7.1
ubuntu
почти 9 лет назад

The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive information or write to arbitrary files via a symlink attack, related to use of the tmpnam function.

CVSS3: 7.1
nvd
почти 9 лет назад

The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive information or write to arbitrary files via a symlink attack, related to use of the tmpnam function.

CVSS3: 7.1
debian
почти 9 лет назад

The make_temporary_filename function in perltidy 20120701-1 and earlie ...

CVSS3: 7.1
github
больше 4 лет назад

The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive information or write to arbitrary files via a symlink attack, related to use of the tmpnam function.

EPSS

Процентиль: 28%
0.00354
Низкий

2.1 Low

CVSS2