Perl 5.004_04 and earlier follows symbolic links when...
Low severity
Unreviewed
Published
Apr 30, 2022
to the GitHub Advisory Database
•
Updated Feb 4, 2024
Description
Published by the National Vulnerability Database
Dec 31, 1999
Published to the GitHub Advisory Database
Apr 30, 2022
Last updated
Feb 4, 2024
Perl 5.004_04 and earlier follows symbolic links when running with the -e option, which allows local users to overwrite arbitrary files via a symlink attack on the /tmp/perl-eaXXXXX file.
References