Vulnerability Description
ProcessTable.pm in the Proc::ProcessTable module 0.45 for Perl, when TTY information caching is enabled, allows local users to overwrite arbitrary files via a symlink attack on /tmp/TTYDEVS.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Frii | Proc\ | \ |
| Perl | Perl | - |
Related Weaknesses (CWE)
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=650500
- http://secunia.com/advisories/47015
- http://www.openwall.com/lists/oss-security/2011/11/30/2
- http://www.openwall.com/lists/oss-security/2011/11/30/3
- http://www.osvdb.org/77428
- http://www.securityfocus.com/bid/50868
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-4363
- https://rt.cpan.org/Public/Bug/Display.html?id=72862
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=650500
- http://secunia.com/advisories/47015
- http://www.openwall.com/lists/oss-security/2011/11/30/2
- http://www.openwall.com/lists/oss-security/2011/11/30/3
- http://www.osvdb.org/77428
- http://www.securityfocus.com/bid/50868
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-4363
FAQ
What is CVE-2011-4363?
CVE-2011-4363 is a vulnerability with a CVSS score of 2.6 (LOW). ProcessTable.pm in the Proc::ProcessTable module 0.45 for Perl, when TTY information caching is enabled, allows local users to overwrite arbitrary files via a symlink attack on /tmp/TTYDEVS.
How severe is CVE-2011-4363?
CVE-2011-4363 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-4363?
Check the references section above for vendor advisories and patch information. Affected products include: Frii Proc\, Perl Perl.