Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-2277

Опубликовано: 03 мар. 2014
Источник: redhat
CVSS2: 2.1

Описание

The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive information or write to arbitrary files via a symlink attack, related to use of the tmpnam function.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6perltidyWill not fix
Red Hat Enterprise Linux 7perltidyNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-377
Дефект:
CWE-367
https://bugzilla.redhat.com/show_bug.cgi?id=1074720perltidy: insecure temporary file creation

2.1 Low

CVSS2

Связанные уязвимости

CVSS3: 7.1
ubuntu
больше 8 лет назад

The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive information or write to arbitrary files via a symlink attack, related to use of the tmpnam function.

CVSS3: 7.1
nvd
больше 8 лет назад

The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive information or write to arbitrary files via a symlink attack, related to use of the tmpnam function.

CVSS3: 7.1
debian
больше 8 лет назад

The make_temporary_filename function in perltidy 20120701-1 and earlie ...

CVSS3: 7.1
github
больше 3 лет назад

The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive information or write to arbitrary files via a symlink attack, related to use of the tmpnam function.

2.1 Low

CVSS2