CVE-2012-2451

high

Description

The Config::IniFiles module before 2.71 for Perl creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack. NOTE: some of these details are obtained from third party information. NOTE: it has been reported that this might only be exploitable by writing in the same directory as the .ini file. If this is the case, then this issue might not cross privilege boundaries.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/75328

https://bugzilla.redhat.com/show_bug.cgi?id=818386

http://www.ubuntu.com/usn/USN-1543-1

http://www.securityfocus.com/bid/53361

http://www.osvdb.org/81671

http://www.openwall.com/lists/oss-security/2012/05/02/6

http://secunia.com/advisories/48990

http://lists.fedoraproject.org/pipermail/package-announce/2012-May/081207.html

http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080716.html

http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080713.html

Details

Source: Mitre, NVD

Published: 2012-06-27

Updated: 2017-08-29

Risk Information

CVSS v2

Base Score: 3.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:P/A:P

Severity: Low

CVSS v3

Base Score: 7.1

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Severity: High