{"api_version":"1","generated_at":"2026-07-23T08:28:45+00:00","cve":"CVE-2008-2827","urls":{"html":"https://cve.report/CVE-2008-2827","api":"https://cve.report/api/cve/CVE-2008-2827.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-2827","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-2827"},"summary":{"title":"CVE-2008-2827","description":"The rmtree function in lib/File/Path.pm in Perl 5.10 does not properly check permissions before performing a chmod, which allows local users to modify the permissions of arbitrary files via a symlink attack, a different vulnerability than CVE-2005-0448 and CVE-2004-0452.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-06-23 19:41:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.6","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://secunia.com/advisories/31687","name":"http://secunia.com/advisories/31687","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SUSE Update for Multiple Packages - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html","name":"http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] SUSE Security Summary Report SUSE-SR:2008:017","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/30790","name":"http://secunia.com/advisories/30790","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Perl \"File::Path::rmtree\" Insecure chmod on Symbolic Links - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=487319","name":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=487319","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"#487319 - perl-modules: File::Path::rmtree sets symlink target permissions to 0777 - Debian Bug report logs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:165","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:165","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Support / Security / Advisories /  / MDVSA-2008:165 | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/29902","name":"http://www.securityfocus.com/bid/29902","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Perl 'rmtree()' Function Local Insecure Permissions Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43308","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43308","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rt.cpan.org/Public/Bug/Display.html?id=36982","name":"http://rt.cpan.org/Public/Bug/Display.html?id=36982","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Bug #36982 for File-Path: rmtree() makes symlink targets world-writable","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/30837","name":"http://secunia.com/advisories/30837","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Fedora update for perl - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1020373","name":"http://www.securitytracker.com/id?1020373","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Perl rmtree() Function Lets Local Users Gain Elevated Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.redhat.com/archives/fedora-package-announce/2008-June/msg01025.html","name":"https://www.redhat.com/archives/fedora-package-announce/2008-June/msg01025.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[SECURITY] Fedora 9 Update: perl-5.10.0-27.fc9","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-2827","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-2827","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"2827","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"perl","cpe5":"perl","cpe6":"5.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2008-2827","organization":"Red Hat","lastmodified":"2008-06-24","contributor":"Mark J Cox","statementText":"Not vulnerable. This issue did not affect the versions of perl as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5, Red Hat Application Stack 1, or Solaris versions of Red Hat Directory Server 7.1 and 8, Certificate System 7.x.","cve_year":"2008","cve_id":"2827","crc32":"d8fcc6da"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T09:14:14.805Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"SUSE-SR:2008:017","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html"},{"name":"FEDORA-2008-5739","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2008-June/msg01025.html"},{"name":"29902","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/29902"},{"name":"MDVSA-2008:165","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:165"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://rt.cpan.org/Public/Bug/Display.html?id=36982"},{"name":"31687","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31687"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=487319"},{"name":"1020373","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1020373"},{"name":"30790","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/30790"},{"name":"30837","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/30837"},{"name":"perl-filepath-rmtree-symlink(43308)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43308"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-06-21T00:00:00.000Z","descriptions":[{"lang":"en","value":"The rmtree function in lib/File/Path.pm in Perl 5.10 does not properly check permissions before performing a chmod, which allows local users to modify the permissions of arbitrary files via a symlink attack, a different vulnerability than CVE-2005-0448 and CVE-2004-0452."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"SUSE-SR:2008:017","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html"},{"name":"FEDORA-2008-5739","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2008-June/msg01025.html"},{"name":"29902","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/29902"},{"name":"MDVSA-2008:165","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:165"},{"tags":["x_refsource_MISC"],"url":"http://rt.cpan.org/Public/Bug/Display.html?id=36982"},{"name":"31687","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31687"},{"tags":["x_refsource_CONFIRM"],"url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=487319"},{"name":"1020373","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1020373"},{"name":"30790","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/30790"},{"name":"30837","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/30837"},{"name":"perl-filepath-rmtree-symlink(43308)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43308"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-2827","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The rmtree function in lib/File/Path.pm in Perl 5.10 does not properly check permissions before performing a chmod, which allows local users to modify the permissions of arbitrary files via a symlink attack, a different vulnerability than CVE-2005-0448 and CVE-2004-0452."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"SUSE-SR:2008:017","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html"},{"name":"FEDORA-2008-5739","refsource":"FEDORA","url":"https://www.redhat.com/archives/fedora-package-announce/2008-June/msg01025.html"},{"name":"29902","refsource":"BID","url":"http://www.securityfocus.com/bid/29902"},{"name":"MDVSA-2008:165","refsource":"MANDRIVA","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:165"},{"name":"http://rt.cpan.org/Public/Bug/Display.html?id=36982","refsource":"MISC","url":"http://rt.cpan.org/Public/Bug/Display.html?id=36982"},{"name":"31687","refsource":"SECUNIA","url":"http://secunia.com/advisories/31687"},{"name":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=487319","refsource":"CONFIRM","url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=487319"},{"name":"1020373","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1020373"},{"name":"30790","refsource":"SECUNIA","url":"http://secunia.com/advisories/30790"},{"name":"30837","refsource":"SECUNIA","url":"http://secunia.com/advisories/30837"},{"name":"perl-filepath-rmtree-symlink(43308)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43308"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-2827","datePublished":"2008-06-23T19:00:00.000Z","dateReserved":"2008-06-23T00:00:00.000Z","dateUpdated":"2024-08-07T09:14:14.805Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-06-23 19:41:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:perl:perl:5.10:*:*:*:*:*:*:*","matchCriteriaId":"777EC860-FB16-4B15-A8BE-3EAE9FD8A99D"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"2827","Ordinal":"1","Title":"CVE-2008-2827","CVE":"CVE-2008-2827","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"2827","Ordinal":"1","NoteData":"The rmtree function in lib/File/Path.pm in Perl 5.10 does not properly check permissions before performing a chmod, which allows local users to modify the permissions of arbitrary files via a symlink attack, a different vulnerability than CVE-2005-0448 and CVE-2004-0452.","Type":"Description","Title":"CVE-2008-2827"},{"CveYear":"2008","CveId":"2827","Ordinal":"2","NoteData":"2008-06-23","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"2827","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}