Описание
The par_mktmpdir function in the PAR module before 1.003 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program, a different vulnerability in a different package than CVE-2011-4114.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 1.005-1 |
| hardy | ignored | end of life |
| lucid | ignored | end of life |
| maverick | ignored | end of life |
| natty | ignored | end of life |
| oneiric | ignored | end of life |
| precise | not-affected | 1.005-1 |
| quantal | not-affected | 1.005-1 |
| raring | not-affected | 1.005-1 |
| saucy | not-affected | 1.005-1 |
Показывать по
Ссылки на источники
EPSS
3.3 Low
CVSS2
Связанные уязвимости
The par_mktmpdir function in the PAR module before 1.003 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program, a different vulnerability in a different package than CVE-2011-4114.
The par_mktmpdir function in the PAR module before 1.003 for Perl crea ...
The par_mktmpdir function in the PAR module before 1.003 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program, a different vulnerability in a different package than CVE-2011-4114.
EPSS
3.3 Low
CVSS2