Description: | Description:
The remote host is missing updates announced in advisory FLSA-2006:152845.
An unsafe file permission bug was discovered in the rmtree() function in the File::Path module. The rmtree() function removes files and directories in an insecure manner, which could allow a local user to read or delete arbitrary files. The Common Vulnerabilities and Exposures project has assigned the name CVE-2004-0452 to this issue.
Solar Designer discovered several temporary file bugs in various Perl modules. A local attacker could overwrite or create files as the user running a Perl script that uses a vulnerable module. The Common Vulner- abilities and Exposures project has assigned the name CVE-2004-0976 to this issue.
Kevin Finisterre discovered a stack based buffer overflow flaw in sperl, the Perl setuid wrapper. A local user could create a sperl executable script with a carefully created path name, overflowing the buffer and leading to root privilege escalation. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2005-0156 to this issue.
Kevin Finisterre discovered a flaw in sperl which can cause debugging information to be logged to arbitrary files. By setting an environment variable, a local user could cause sperl to create, as root, files with arbitrary filenames, or append the debugging information to existing files. The Common Vulnerabilities and Exposures project has assigned the name CVE-2005-0155 to this issue.
Paul Szabo discovered a bug in the way Perl's File::Path::rmtree module removed directory trees. If a local user has write permissions to a subdirectory within the tree being removed by File::Path::rmtree, it is possible for them to create setuid binary files. The Common Vulner- abilities and Exposures project has assigned the name CVE-2005-0448 to this issue. (This issue updates CVE-2004-0452).
Users of perl are advised to upgrade to these packages which contain backported patches and are not vulnerable to these issues.
Affected platforms: Redhat 7.3 Redhat 9 Fedora Core 1 Fedora Core 2
Solution: http://www.securityspace.com/smysecure/catid.html?in=FLSA-2006:152845
Risk factor : Medium
CVSS Score: 4.6
|