[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248585

 
 

909

 
 

195621

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-1875Date: (C)2014-10-07   (M)2023-12-22


The Capture::Tiny module before 0.24 for Perl allows local users to write to arbitrary files via a symlink attack on a temporary file.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 3.6
Exploit Score: 3.9
Impact Score: 4.9
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
OSVDB-102963
SECUNIA-56823
BID-65475
FEDORA-2014-2261
FEDORA-2014-2321
http://seclists.org/oss-sec/2014/q1/267
http://seclists.org/oss-sec/2014/q1/272
capturetiny-perl-symlink(91464)
http://cpansearch.perl.org/src/DAGOLDEN/Capture-Tiny-0.24/Changes
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737835
https://bugzilla.redhat.com/show_bug.cgi?id=1062424
https://github.com/dagolden/Capture-Tiny/commit/635c9eabd52ab8042b0c841823bd6e692de87924
https://github.com/dagolden/Capture-Tiny/issues/16

CWE    1
CWE-59
OVAL    3
oval:org.secpod.oval:def:106441
oval:org.secpod.oval:def:106422
oval:org.secpod.oval:def:1600142

© SecPod Technologies