SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-2451

The Config::IniFiles module before 2.71 for Perl creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.

LOW 3.6EPSS 0.50%

Does this matter?

Lower severity and a low EPSS score (0.50%). Track it; it rarely justifies an emergency change on its own.

Description

The Config::IniFiles module before 2.71 for Perl creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack. NOTE: some of these details are obtained from third party information. NOTE: it has been reported that this might only be exploitable by writing in the same directory as the .ini file. If this is the case, then this issue might not cross privilege boundaries.

CVSS 2.0
3.6 LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
EPSS
0.50% probability · 42th percentile
CISA KEV
Not listed
Affected
shlomi fish/config-inifiles
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.