Vulnerability Name: | CVE-2004-0452 (CCN-18650) | ||||||||||||||||||||||||||||||||
Assigned: | 2004-12-21 | ||||||||||||||||||||||||||||||||
Published: | 2004-12-21 | ||||||||||||||||||||||||||||||||
Updated: | 2017-10-11 | ||||||||||||||||||||||||||||||||
Summary: | Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for the world, which allows local users to delete arbitrary files and directories, and possibly read files and directories, via a symlink attack. | ||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 2.9 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 2.6 Low (CVSS v2 Vector: AV:L/AC:H/Au:N/C:N/I:P/A:P)
| ||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||||||||||||||
References: | Source: SGI Type: UNKNOWN 20060101-01-U Source: MITRE Type: CNA CVE-2004-0452 Source: FEDORA Type: UNKNOWN FLSA-2006:152845 Source: BUGTRAQ Type: UNKNOWN 20050111 [OpenPKG-SA-2005.001] OpenPKG Security Advisory (perl) Source: CCN Type: RHSA-2005-103 perl security update Source: CCN Type: RHSA-2005-105 perl security update Source: CCN Type: SA12991 Perl Multiple Scripts Insecure Temporary File Creation Vulnerabilities Source: SECUNIA Type: UNKNOWN 12991 Source: SECUNIA Type: UNKNOWN 18517 Source: CCN Type: SA55314 Oracle Solaris Perl Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 55314 Source: CCN Type: CIAC Information Bulletin P-086 Perl Insecure Temporary Files/Directories Source: DEBIAN Type: Patch, Vendor Advisory DSA-620 Source: DEBIAN Type: DSA-1678 perl -- design flaws Source: DEBIAN Type: DSA-620 perl -- insecure temporary files / directories Source: CCN Type: GLSA-200501-38 Perl: rmtree and DBI tmpfile vulnerabilities Source: GENTOO Type: Patch, Vendor Advisory GLSA-200501-38 Source: CCN Type: OpenPKG-SA-2005.001 Perl File::Path Source: REDHAT Type: Patch, Vendor Advisory RHSA-2005:103 Source: REDHAT Type: UNKNOWN RHSA-2005:105 Source: BID Type: UNKNOWN 12072 Source: CCN Type: BID-12072 Perl RMTree Local Race Condition Vulnerability Source: CCN Type: TLSA-2005-35 Symlink attack in perl may allow arbitrary file overwriting Source: CCN Type: USN-44-1 perl information leak Source: XF Type: UNKNOWN perl-filepathrmtree-insecure-permissions(18650) Source: XF Type: UNKNOWN perl-filepathrmtree-insecure-permissions(18650) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:9938 Source: SUSE Type: SUSE-SR:2005:004 SUSE Security Summary Report Source: UBUNTU Type: UNKNOWN USN-44-1 | ||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||
BACK |