Lucene search

K
cveMitreCVE-2012-2451
HistoryJun 27, 2012 - 9:55 p.m.

CVE-2012-2451

2012-06-2721:55:03
mitre
web.nvd.nist.gov
53
cve-2012-2451
config::inifiles
perl
temporary files
symlink attack
local users
security vulnerability
nvd

CVSS2

3.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:P/A:P

AI Score

6

Confidence

Low

EPSS

0

Percentile

5.1%

The Config::IniFiles module before 2.71 for Perl creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack. NOTE: some of these details are obtained from third party information. NOTE: it has been reported that this might only be exploitable by writing in the same directory as the .ini file. If this is the case, then this issue might not cross privilege boundaries.

Affected configurations

Nvd
Node
shlomi_fishconfig-inifilesRangeโ‰ค2.70
VendorProductVersionCPE
shlomi_fishconfig-inifiles*cpe:2.3:a:shlomi_fish:config-inifiles:*:*:*:*:*:*:*:*

CVSS2

3.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:P/A:P

AI Score

6

Confidence

Low

EPSS

0

Percentile

5.1%