Perl Perltidy Package CVE-2014-2277 Insecure File Creation Vulnerability
BID:66139
Info
Perl Perltidy Package CVE-2014-2277 Insecure File Creation Vulnerability
| Bugtraq ID: | 66139 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2277 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 08 2014 12:00AM |
| Updated: | Apr 13 2015 10:08PM |
| Credit: | Jakub Wilk |
| Vulnerable: |
Steve Hancock perltidy 20120701-1 Steve Hancock perltidy 0 |
| Not Vulnerable: |
Steve Hancock perltidy 20130922-1 |
Discussion
Perl Perltidy Package CVE-2014-2277 Insecure File Creation Vulnerability
Perl Perltidy package is prone to an insecure file-creation vulnerability.
Successfully mounting a symlink attack may allow the attacker to corrupt sensitive files or gain access to sensitive information. Other attacks may also be possible.
Perl Perltidy package is prone to an insecure file-creation vulnerability.
Successfully mounting a symlink attack may allow the attacker to corrupt sensitive files or gain access to sensitive information. Other attacks may also be possible.
Solution / Fix
Perl Perltidy Package CVE-2014-2277 Insecure File Creation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.