Vulnerability Description
Perl 5.004_04 and earlier follows symbolic links when running with the -e option, which allows local users to overwrite arbitrary files via a symlink attack on the /tmp/perl-eaXXXXX file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Perl | Perl | <= 5.004_04 |
Related Weaknesses (CWE)
References
- http://marc.info/?l=bugtraq&m=88932165406213&w=2ExploitMailing List
- http://www.iss.net/security_center/static/7243.phpBroken Link
- http://www.redhat.com/support/errata/rh50-errata-general.html#perlBroken Link
- http://marc.info/?l=bugtraq&m=88932165406213&w=2ExploitMailing List
- http://www.iss.net/security_center/static/7243.phpBroken Link
- http://www.redhat.com/support/errata/rh50-errata-general.html#perlBroken Link
FAQ
What is CVE-1999-1386?
CVE-1999-1386 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Perl 5.004_04 and earlier follows symbolic links when running with the -e option, which allows local users to overwrite arbitrary files via a symlink attack on the /tmp/perl-eaXXXXX file.
How severe is CVE-1999-1386?
CVE-1999-1386 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-1999-1386?
Check the references section above for vendor advisories and patch information. Affected products include: Perl Perl.