CPAN Data::UUID Module Insecure Temporary File Handling Vulnerability
BID:61534
CVE-2013-4184 |Info
CPAN Data::UUID Module Insecure Temporary File Handling Vulnerability
| Bugtraq ID: | 61534 |
| Class: | Design Error |
| CVE: |
CVE-2013-4184 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 30 2013 12:00AM |
| Updated: | Jul 30 2013 12:00AM |
| Credit: | Tim Retout |
| Vulnerable: |
CPAN Data::UUID 1.219 |
| Not Vulnerable: | |
Discussion
CPAN Data::UUID Module Insecure Temporary File Handling Vulnerability
Data::UUID is prone to an insecure temporary file-handling vulnerability.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Data::UUID 1.219 is vulnerable; other versions may also be affected.
Data::UUID is prone to an insecure temporary file-handling vulnerability.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Data::UUID 1.219 is vulnerable; other versions may also be affected.
Exploit / POC
CPAN Data::UUID Module Insecure Temporary File Handling Vulnerability
An attacker can use readily available commands to exploit this issue.
An attacker can use readily available commands to exploit this issue.
References
CPAN Data::UUID Module Insecure Temporary File Handling Vulnerability
References:
References: