CPAN PAR::Packer Module Insecure Temporary Directory Creation Vulnerability
BID:50540
Info
CPAN PAR::Packer Module Insecure Temporary Directory Creation Vulnerability
| Bugtraq ID: | 50540 |
| Class: | Design Error |
| CVE: |
CVE-2011-4114 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 04 2011 12:00AM |
| Updated: | Apr 13 2015 09:52PM |
| Credit: | John Lightsey |
| Vulnerable: |
CPAN PAR::Packer 0 Audrey Tang PAR-Packer Module 1.010 Audrey Tang PAR-Packer Module 1.002 Audrey Tang PAR Module 1.002 |
| Not Vulnerable: |
Audrey Tang PAR-Packer Module 1.011 Audrey Tang PAR Module 1.003 |
Discussion
CPAN PAR::Packer Module Insecure Temporary Directory Creation Vulnerability
CPAN PAR::Packer module creates a temporary directory in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks. Other attacks may also be possible.
CPAN PAR::Packer module creates a temporary directory in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks. Other attacks may also be possible.
Exploit / POC
CPAN PAR::Packer Module Insecure Temporary Directory Creation Vulnerability
An attacker can use readily available commands to exploit this issue.
An attacker can use readily available commands to exploit this issue.
Solution / Fix
CPAN PAR::Packer Module Insecure Temporary Directory Creation Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
CPAN PAR::Packer Module Insecure Temporary Directory Creation Vulnerability
References:
References:
- [Changes for 1.003 - Nov 28, 2011] (Aubrey Tang)
- Bug #69560 for PAR-Packer: PAR packed files are extracted to unsafe and predicta (Audrey Tang )
- CPAN Homepage (Lincoln D. Stein)
- PAR packed files are extracted to unsafe and predictable temporary directories (CPAN)