Perl 5.004_04 and earlier follows symbolic links when running with the -e option, which allows local users to overwrite arbitrary files via a symlink attack on the /tmp/perl-eaXXXXX file.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Perl |
Larry_wall |
* |
5.4.4 |
References