Perl 5.004_04 and earlier follows symbolic links when running with the -e option, which allows local users to overwrite arbitrary files via a symlink attack on the /tmp/perl-eaXXXXX file.
References
Configurations
Information
Published : 1999-12-30 21:00
Updated : 2016-10-17 19:03
NVD link : CVE-1999-1386
Mitre link : CVE-1999-1386
JSON object : View
CWE
Products Affected
larry_wall
- perl