Vulnerability CVE-2012-2451


Published: 2012-06-27

Description:
The Config::IniFiles module before 2.71 for Perl creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack. NOTE: some of these details are obtained from third party information. NOTE: it has been reported that this might only be exploitable by writing in the same directory as the .ini file. If this is the case, then this issue might not cross privilege boundaries.

Vendor: Shlomi fish
Product: Config-inifiles 
Version: 2.70;

CVSS2 => (AV:L/AC:L/Au:N/C:N/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
3.6/10
4.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
Partial

 References:
https://bitbucket.org/shlomif/perl-config-inifiles/changeset/a08fa26f4f59
https://bugzilla.redhat.com/show_bug.cgi?id=818386
http://www.osvdb.org/81671
http://www.openwall.com/lists/oss-security/2012/05/02/6
http://secunia.com/advisories/48990
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/081207.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080716.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080713.html

Copyright 2019, cxsecurity.com

 

Back to Top