CVE-2014-1875

The Capture::Tiny module before 0.24 for Perl allows local users to write to arbitrary files via a symlink attack on a temporary file.
References
Link Resource
http://cpansearch.perl.org/src/DAGOLDEN/Capture-Tiny-0.24/Changes
http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128823.html
http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128882.html
http://osvdb.org/102963
http://seclists.org/oss-sec/2014/q1/267 Exploit
http://seclists.org/oss-sec/2014/q1/272
http://secunia.com/advisories/56823
http://www.securityfocus.com/bid/65475
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737835 Exploit
https://bugzilla.redhat.com/show_bug.cgi?id=1062424
https://exchange.xforce.ibmcloud.com/vulnerabilities/91464
https://github.com/dagolden/Capture-Tiny/commit/635c9eabd52ab8042b0c841823bd6e692de87924
https://github.com/dagolden/Capture-Tiny/issues/16 Exploit
http://cpansearch.perl.org/src/DAGOLDEN/Capture-Tiny-0.24/Changes
http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128823.html
http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128882.html
http://osvdb.org/102963
http://seclists.org/oss-sec/2014/q1/267 Exploit
http://seclists.org/oss-sec/2014/q1/272
http://secunia.com/advisories/56823
http://www.securityfocus.com/bid/65475
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737835 Exploit
https://bugzilla.redhat.com/show_bug.cgi?id=1062424
https://exchange.xforce.ibmcloud.com/vulnerabilities/91464
https://github.com/dagolden/Capture-Tiny/commit/635c9eabd52ab8042b0c841823bd6e692de87924
https://github.com/dagolden/Capture-Tiny/issues/16 Exploit
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cspan:capture-tiny:*:*:*:*:*:*:*:*
cpe:2.3:a:cspan:capture-tiny:0.20:*:*:*:*:*:*:*
cpe:2.3:a:cspan:capture-tiny:0.21:*:*:*:*:*:*:*
cpe:2.3:a:cspan:capture-tiny:0.22:*:*:*:*:*:*:*

History

21 Nov 2024, 02:05

Type Values Removed Values Added
References () http://cpansearch.perl.org/src/DAGOLDEN/Capture-Tiny-0.24/Changes - () http://cpansearch.perl.org/src/DAGOLDEN/Capture-Tiny-0.24/Changes -
References () http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128823.html - () http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128823.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128882.html - () http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128882.html -
References () http://osvdb.org/102963 - () http://osvdb.org/102963 -
References () http://seclists.org/oss-sec/2014/q1/267 - Exploit () http://seclists.org/oss-sec/2014/q1/267 - Exploit
References () http://seclists.org/oss-sec/2014/q1/272 - () http://seclists.org/oss-sec/2014/q1/272 -
References () http://secunia.com/advisories/56823 - () http://secunia.com/advisories/56823 -
References () http://www.securityfocus.com/bid/65475 - () http://www.securityfocus.com/bid/65475 -
References () https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737835 - Exploit () https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737835 - Exploit
References () https://bugzilla.redhat.com/show_bug.cgi?id=1062424 - () https://bugzilla.redhat.com/show_bug.cgi?id=1062424 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/91464 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/91464 -
References () https://github.com/dagolden/Capture-Tiny/commit/635c9eabd52ab8042b0c841823bd6e692de87924 - () https://github.com/dagolden/Capture-Tiny/commit/635c9eabd52ab8042b0c841823bd6e692de87924 -
References () https://github.com/dagolden/Capture-Tiny/issues/16 - Exploit () https://github.com/dagolden/Capture-Tiny/issues/16 - Exploit

Information

Published : 2014-10-06 23:55

Updated : 2024-11-21 02:05


NVD link : CVE-2014-1875

Mitre link : CVE-2014-1875

CVE.ORG link : CVE-2014-1875


JSON object : View

Products Affected

cspan

  • capture-tiny
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')