FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2012-2451

This CVE name corresponds to:

Entered Topic
2012-05-07 p5-Config-IniFiles -- unsafe temporary file creation

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2012-2451
Phase Assigned(20120502)

Description

The Config::IniFiles module before 2.71 for Perl creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack. NOTE: some of these details are obtained from third party information. NOTE: it has been reported that this might only be exploitable by writing in the same directory as the .ini file. If this is the case, then this issue might not cross privilege boundaries.

References

Source Reference
MLIST [oss-security] 20120502 temporary file issue in Config::IniFiles Config-IniFiles perl-Config-IniFiles
MISC https://bugzilla.redhat.com/show_bug.cgi?id=818386
CONFIRM https://bitbucket.org/shlomif/perl-config-inifiles/changeset/a08fa26f4f59
FEDORA FEDORA-2012-7763
FEDORA FEDORA-2012-7777
FEDORA FEDORA-2012-7802
UBUNTU USN-1543-1
BID 53361
OSVDB 81671
SECUNIA 48990
XF config-inifiles-symlink(75328)