perltidy's maketemporaryfilename() function insecurely created temporary files via the use of the tmpnam() function. A local attacker could use this flaw to perform a symbolic link attack (CVE-2014-2277).
{ "section": "core" }