2.1
CVSSv2

CVE-2004-0976

Published: 09/02/2005 Updated: 11/10/2017
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple scripts in the perl package in Trustix Secure Linux 1.5 up to and including 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files.

Vulnerable Product Search on Vulmon Subscribe to Product

larry wall perl 5.6

larry wall perl 5.6.1

larry wall perl 5.8.0

larry wall perl 5.8.1

larry wall perl 5.8.3

Vendor Advisories

Synopsis perl security update Type/Severity Security Advisory: Moderate Topic Updated Perl packages that fix security issues and bugs are now availablefor Red Hat Enterprise Linux 3This update has been rated as having moderate security impact by the RedHat Security Response Team Description ...
Recently, Trustix Secure Linux discovered some vulnerabilities in the perl package The utility “instmodsh”, the Perl package “PPPortpm”, and several test scripts (which are not shipped and only used during build) created temporary files in an insecure way, which could allow a symlink attack to create or overwrite arbitrary files with the ...