CVE-2012-2451

Source
https://nvd.nist.gov/vuln/detail/CVE-2012-2451
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2012-2451.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2012-2451
Related
Published
2012-06-27T21:55:03Z
Modified
2024-11-21T01:39:07Z
Summary
[none]
Details

The Config::IniFiles module before 2.71 for Perl creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack. NOTE: some of these details are obtained from third party information. NOTE: it has been reported that this might only be exploitable by writing in the same directory as the .ini file. If this is the case, then this issue might not cross privilege boundaries.

References

Affected packages

Debian:11 / libconfig-inifiles-perl

Package

Name
libconfig-inifiles-perl
Purl
pkg:deb/debian/libconfig-inifiles-perl?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.72-1

Ecosystem specific

{
    "urgency": "low"
}

Debian:12 / libconfig-inifiles-perl

Package

Name
libconfig-inifiles-perl
Purl
pkg:deb/debian/libconfig-inifiles-perl?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.72-1

Ecosystem specific

{
    "urgency": "low"
}

Debian:13 / libconfig-inifiles-perl

Package

Name
libconfig-inifiles-perl
Purl
pkg:deb/debian/libconfig-inifiles-perl?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.72-1

Ecosystem specific

{
    "urgency": "low"
}