Lucene search

K
cveRedhatCVE-2011-4114
HistoryJan 13, 2012 - 6:55 p.m.

CVE-2011-4114

2012-01-1318:55:03
CWE-264
redhat
web.nvd.nist.gov
34
cve-2011-4114
par::packer
perl
vulnerability
file overwrite
nvd

CVSS2

3.3

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:N/I:P/A:P

AI Score

6

Confidence

Low

EPSS

0

Percentile

5.1%

The par_mktmpdir function in the PAR::Packer module before 1.012 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program. NOTE: a similar vulnerability was reported for PAR, but this has been assigned a different CVE identifier.

Affected configurations

Nvd
Node
roderich_schupppar-packer_moduleRange1.011
OR
roderich_schupppar-packer_moduleMatch0.63
OR
roderich_schupppar-packer_moduleMatch0.64
OR
roderich_schupppar-packer_moduleMatch0.65
OR
roderich_schupppar-packer_moduleMatch0.66
OR
roderich_schupppar-packer_moduleMatch0.67
OR
roderich_schupppar-packer_moduleMatch0.68
OR
roderich_schupppar-packer_moduleMatch0.69
OR
roderich_schupppar-packer_moduleMatch0.70
OR
roderich_schupppar-packer_moduleMatch0.71
OR
roderich_schupppar-packer_moduleMatch0.72
OR
roderich_schupppar-packer_moduleMatch0.73
OR
roderich_schupppar-packer_moduleMatch0.74
OR
roderich_schupppar-packer_moduleMatch0.75
OR
roderich_schupppar-packer_moduleMatch0.76
OR
roderich_schupppar-packer_moduleMatch0.77
OR
roderich_schupppar-packer_moduleMatch0.78
OR
roderich_schupppar-packer_moduleMatch0.79
OR
roderich_schupppar-packer_moduleMatch0.80
OR
roderich_schupppar-packer_moduleMatch0.81
OR
roderich_schupppar-packer_moduleMatch0.82
OR
roderich_schupppar-packer_moduleMatch0.83
OR
roderich_schupppar-packer_moduleMatch0.85
OR
roderich_schupppar-packer_moduleMatch0.86
OR
roderich_schupppar-packer_moduleMatch0.87
OR
roderich_schupppar-packer_moduleMatch0.88
OR
roderich_schupppar-packer_moduleMatch0.89
OR
roderich_schupppar-packer_moduleMatch0.90
OR
roderich_schupppar-packer_moduleMatch0.91
OR
roderich_schupppar-packer_moduleMatch0.92
OR
roderich_schupppar-packer_moduleMatch0.93
OR
roderich_schupppar-packer_moduleMatch0.94
OR
roderich_schupppar-packer_moduleMatch0.941
OR
roderich_schupppar-packer_moduleMatch0.942
OR
roderich_schupppar-packer_moduleMatch0.951
OR
roderich_schupppar-packer_moduleMatch0.952
OR
roderich_schupppar-packer_moduleMatch0.953
OR
roderich_schupppar-packer_moduleMatch0.954
OR
roderich_schupppar-packer_moduleMatch0.955
OR
roderich_schupppar-packer_moduleMatch0.956
OR
roderich_schupppar-packer_moduleMatch0.957
OR
roderich_schupppar-packer_moduleMatch0.958
OR
roderich_schupppar-packer_moduleMatch0.959
OR
roderich_schupppar-packer_moduleMatch0.960
OR
roderich_schupppar-packer_moduleMatch0.970
OR
roderich_schupppar-packer_moduleMatch0.973
OR
roderich_schupppar-packer_moduleMatch0.975
OR
roderich_schupppar-packer_moduleMatch0.976
OR
roderich_schupppar-packer_moduleMatch0.977
OR
roderich_schupppar-packer_moduleMatch0.978
OR
roderich_schupppar-packer_moduleMatch0.979
OR
roderich_schupppar-packer_moduleMatch0.980
OR
roderich_schupppar-packer_moduleMatch0.981
OR
roderich_schupppar-packer_moduleMatch0.982
OR
roderich_schupppar-packer_moduleMatch0.991
OR
roderich_schupppar-packer_moduleMatch0.992_01
OR
roderich_schupppar-packer_moduleMatch0.992_02
OR
roderich_schupppar-packer_moduleMatch0.992_03
OR
roderich_schupppar-packer_moduleMatch0.992_04
OR
roderich_schupppar-packer_moduleMatch0.992_05
OR
roderich_schupppar-packer_moduleMatch0.992_06
OR
roderich_schupppar-packer_moduleMatch1.000
OR
roderich_schupppar-packer_moduleMatch1.001
OR
roderich_schupppar-packer_moduleMatch1.002
OR
roderich_schupppar-packer_moduleMatch1.003
OR
roderich_schupppar-packer_moduleMatch1.004
OR
roderich_schupppar-packer_moduleMatch1.005
OR
roderich_schupppar-packer_moduleMatch1.006
OR
roderich_schupppar-packer_moduleMatch1.007
OR
roderich_schupppar-packer_moduleMatch1.008
OR
roderich_schupppar-packer_moduleMatch1.009
OR
roderich_schupppar-packer_moduleMatch1.010
VendorProductVersionCPE
roderich_schupppar-packer_module*cpe:2.3:a:roderich_schupp:par-packer_module:*:*:*:*:*:*:*:*
roderich_schupppar-packer_module0.63cpe:2.3:a:roderich_schupp:par-packer_module:0.63:*:*:*:*:*:*:*
roderich_schupppar-packer_module0.64cpe:2.3:a:roderich_schupp:par-packer_module:0.64:*:*:*:*:*:*:*
roderich_schupppar-packer_module0.65cpe:2.3:a:roderich_schupp:par-packer_module:0.65:*:*:*:*:*:*:*
roderich_schupppar-packer_module0.66cpe:2.3:a:roderich_schupp:par-packer_module:0.66:*:*:*:*:*:*:*
roderich_schupppar-packer_module0.67cpe:2.3:a:roderich_schupp:par-packer_module:0.67:*:*:*:*:*:*:*
roderich_schupppar-packer_module0.68cpe:2.3:a:roderich_schupp:par-packer_module:0.68:*:*:*:*:*:*:*
roderich_schupppar-packer_module0.69cpe:2.3:a:roderich_schupp:par-packer_module:0.69:*:*:*:*:*:*:*
roderich_schupppar-packer_module0.70cpe:2.3:a:roderich_schupp:par-packer_module:0.70:*:*:*:*:*:*:*
roderich_schupppar-packer_module0.71cpe:2.3:a:roderich_schupp:par-packer_module:0.71:*:*:*:*:*:*:*
Rows per page:
1-10 of 721

CVSS2

3.3

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:N/I:P/A:P

AI Score

6

Confidence

Low

EPSS

0

Percentile

5.1%