Perl Config::IniFiles Module Insecure Temporary File Creation Vulnerability
BID:53361
Info
Perl Config::IniFiles Module Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 53361 |
| Class: | Design Error |
| CVE: |
CVE-2012-2451 |
| Remote: | No |
| Local: | Yes |
| Published: | May 02 2012 12:00AM |
| Updated: | Apr 16 2015 06:13PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Perl Foundation Config::IniFiles 2.7 Gentoo Linux |
| Not Vulnerable: |
Perl Foundation Config::IniFiles 2.7.1 |
Discussion
Perl Config::IniFiles Module Insecure Temporary File Creation Vulnerability
The Config::IniFiles module of Perl is prone to a vulnerability because it creates temporary files in an insecure manner.
Successfully mounting a symlink attack may allow the attacker to corrupt sensitive files or gain access to sensitive information. Other attacks may also be possible.
Config::IniFiles versions prior to 2.71 are vulnerable.
The Config::IniFiles module of Perl is prone to a vulnerability because it creates temporary files in an insecure manner.
Successfully mounting a symlink attack may allow the attacker to corrupt sensitive files or gain access to sensitive information. Other attacks may also be possible.
Config::IniFiles versions prior to 2.71 are vulnerable.
Exploit / POC
Perl Config::IniFiles Module Insecure Temporary File Creation Vulnerability
An attacker can use readily available commands to exploit this issue.
An attacker can use readily available commands to exploit this issue.
References
Perl Config::IniFiles Module Insecure Temporary File Creation Vulnerability
References:
References:
- Config-IniFiles Homepage (Perl)
- Fix the temporary filename problem (Perl)