Lucene search

K
freebsdFreeBSD8CFB6F42-D2B0-11DA-A672-000E0C2E438A
HistoryJan 25, 2005 - 12:00 a.m.

p5-DBI -- insecure temporary file creation vulnerability

2005-01-2500:00:00
vuxml.freebsd.org
13

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

EPSS

0

Percentile

5.1%

Javier Fernández-Sanguino Peña reports:

The DBI library, the Perl5 database interface, creates a
temporary PID file in an insecure manner. This can be
exploited by a malicious user to overwrite arbitrary files
owned by the person executing the parts of the library.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchp5-dbi-137= 0UNKNOWN
FreeBSDanynoarchp5-dbi< 1.37_1UNKNOWN

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

EPSS

0

Percentile

5.1%