VulnerabilityModified
CVE-2005-0155
The PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to create arbitrary files via the PERLIO_DEBUG variable.
MEDIUM 4.6EPSS 1.20%
Does this matter?
Lower severity and a low EPSS score (1.20%). Track it; it rarely justifies an emergency change on its own.
Description
The PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to create arbitrary files via the PERLIO_DEBUG variable.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.20% probability · 66th percentile
- CISA KEV
- Not listed
- Affected
- larry wall/perl
- Source
- cve@mitre.org
References
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=001056
- http://fedoranews.org/updates/FEDORA--.shtml
- http://marc.info/?l=bugtraq&m=110737149402683&w=2
- http://marc.info/?l=full-disclosure&m=110779723332339&w=2
- http://secunia.com/advisories/14120
- http://secunia.com/advisories/21646
- http://support.avaya.com/elmodocs2/security/ASA-2006-163.htm
- http://www.digitalmunition.com/DMA%5B2005-0131a%5D.txt
- http://www.gentoo.org/security/en/glsa/glsa-200502-13.xmlPatch, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:031
- http://www.redhat.com/support/errata/RHSA-2005-103.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2005-105.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/12426Exploit, Patch, Vendor Advisory
- http://www.trustix.org/errata/2005/0003/Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19207
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10404
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=001056
- http://fedoranews.org/updates/FEDORA--.shtml
- http://marc.info/?l=bugtraq&m=110737149402683&w=2
- http://marc.info/?l=full-disclosure&m=110779723332339&w=2
- http://secunia.com/advisories/14120
- http://secunia.com/advisories/21646
- http://support.avaya.com/elmodocs2/security/ASA-2006-163.htm
- http://www.digitalmunition.com/DMA%5B2005-0131a%5D.txt
- http://www.gentoo.org/security/en/glsa/glsa-200502-13.xmlPatch, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:031
- http://www.redhat.com/support/errata/RHSA-2005-103.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2005-105.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/12426Exploit, Patch, Vendor Advisory
- http://www.trustix.org/errata/2005/0003/Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.