3.6
CVSSv2

CVE-2014-2277

Published: 17/10/2017 Updated: 04/02/2020
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.1 | Impact Score: 5.2 | Exploitability Score: 1.8
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

The make_temporary_filename function in perltidy 20120701-1 and previous versions allows local users to obtain sensitive information or write to arbitrary files via a symlink attack, related to use of the tmpnam function.

Vulnerable Product Search on Vulmon Subscribe to Product

perltidy project perltidy

Vendor Advisories

Debian Bug report logs - #740670 perltidy: insecure permissions of temporary files Package: perltidy; Maintainer for perltidy is Don Armstrong <don@debianorg>; Source for perltidy is src:perltidy (PTS, buildd, popcon) Reported by: Jakub Wilk <jwilk@debianorg> Date: Mon, 3 Mar 2014 22:30:01 UTC Severity: normal Ta ...
It was discovered that perltidy's make_temporary_filename() function insecurely created temporary files via the use of the tmpnam() function A local attacker could use this flaw to perform a symbolic link attack ...
The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive information or write to arbitrary files via a symlink attack, related to use of the tmpnam function ...