CVE-2011-4114
Publication date 13 January 2012
Last updated 24 July 2024
Ubuntu priority
The par_mktmpdir function in the PAR::Packer module before 1.012 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program. NOTE: a similar vulnerability was reported for PAR, but this has been assigned a different CVE identifier.
Status
Package | Ubuntu Release | Status |
---|---|---|
libpar-packer-perl | ||
libpar-perl | ||
Notes
sbeattie
libpar-perl issued the fix for this issue annotated with CVE-2011-4114; however, it subsequently got split out into a separate cve, CVE-2011-5060.