CVE-2008-2827
Summary
| CVE | CVE-2008-2827 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-06-23 19:41:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The rmtree function in lib/File/Path.pm in Perl 5.10 does not properly check permissions before performing a chmod, which allows local users to modify the permissions of arbitrary files via a symlink attack, a different vulnerability than CVE-2005-0448 and CVE-2004-0452. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SUSE Update for Multiple Packages - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [security-announce] SUSE Security Summary Report SUSE-SR:2008:017 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Perl "File::Path::rmtree" Insecure chmod on Symbolic Links - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| #487319 - perl-modules: File::Path::rmtree sets symlink target permissions to 0777 - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | Exploit |
| Support / Security / Advisories / / MDVSA-2008:165 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Perl 'rmtree()' Function Local Insecure Permissions Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Bug #36982 for File-Path: rmtree() makes symlink targets world-writable | af854a3a-2127-422b-91ae-364da2661108 | rt.cpan.org | Exploit |
| Fedora update for perl - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Perl rmtree() Function Lets Local Users Gain Elevated Privileges - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| [SECURITY] Fedora 9 Update: perl-5.10.0-27.fc9 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2008-06-24 | Mark J Cox | Not vulnerable. This issue did not affect the versions of perl as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5, Red Hat Application Stack 1, or Solaris versions of Red Hat Directory Server 7.1 and 8, Certificate System 7.x. |
There are currently no legacy QID mappings associated with this CVE.