2.1
CVSSv2

CVE-2005-0077

Published: 02/05/2005 Updated: 19/10/2018
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 3.0

gentoo linux

redhat enterprise linux 4.0

redhat enterprise linux desktop 4.0

ubuntu ubuntu linux 4.10

Vendor Advisories

Javier Fern�ndez-Sanguino Pe�a from the Debian Security Audit Project discovered that the module DBI::ProxyServer in Perl’s DBI library created a PID file in an insecure manner This could allow a symbolic link attack to create or overwrite arbitrary files with the privileges of the user invoking a program using this module (like ‘dbiproxy� ...
Synopsis perl security update Type/Severity Security Advisory: Low Topic An updated perl-DBI package that fixes a temporary file flaw inDBI::ProxyServer is now available Description DBI is a database access Application Programming Interface (API) forthe Perl programming language The Debia ...
Synopsis perl-DBI security update Type/Severity Security Advisory: Low Topic An updated perl-DBI package that fixes a temporary file flaw inDBI::ProxyServer is now available for Red Hat Enterprise Linux 4This update has been rated as having low security impact by the Red HatSecurity Response Team ...