Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2012-2451
Description:The Config::IniFiles module before 2.71 for Perl creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack. NOTE: some of these details are obtained from third party information. NOTE: it has been reported that this might only be exploitable by writing in the same directory as the .ini file. If this is the case, then this issue might not cross privilege boundaries.
Test IDs: 1.3.6.1.4.1.25623.1.0.864441   1.3.6.1.4.1.25623.1.0.71855   1.3.6.1.4.1.25623.1.0.841119   1.3.6.1.4.1.25623.1.0.71383   1.3.6.1.4.1.25623.1.0.864252   1.3.6.1.4.1.25623.1.0.864244  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2012-2451
BugTraq ID: 53361
http://www.securityfocus.com/bid/53361
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/081207.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080716.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080713.html
https://bugzilla.redhat.com/show_bug.cgi?id=818386
http://www.openwall.com/lists/oss-security/2012/05/02/6
http://www.osvdb.org/81671
http://secunia.com/advisories/48990
http://www.ubuntu.com/usn/USN-1543-1
XForce ISS Database: config-inifiles-symlink(75328)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75328




© 1998-2025 E-Soft Inc. All rights reserved.