The Capture::Tiny module before 0.24 for Perl allows local users to write to arbitrary files via a symlink attack on a temporary file.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:05
Type | Values Removed | Values Added |
---|---|---|
References | () http://cpansearch.perl.org/src/DAGOLDEN/Capture-Tiny-0.24/Changes - | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128823.html - | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128882.html - | |
References | () http://osvdb.org/102963 - | |
References | () http://seclists.org/oss-sec/2014/q1/267 - Exploit | |
References | () http://seclists.org/oss-sec/2014/q1/272 - | |
References | () http://secunia.com/advisories/56823 - | |
References | () http://www.securityfocus.com/bid/65475 - | |
References | () https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737835 - Exploit | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=1062424 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/91464 - | |
References | () https://github.com/dagolden/Capture-Tiny/commit/635c9eabd52ab8042b0c841823bd6e692de87924 - | |
References | () https://github.com/dagolden/Capture-Tiny/issues/16 - Exploit |
Information
Published : 2014-10-06 23:55
Updated : 2024-11-21 02:05
NVD link : CVE-2014-1875
Mitre link : CVE-2014-1875
CVE.ORG link : CVE-2014-1875
JSON object : View
Products Affected
cspan
- capture-tiny
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')