CVE Vulnerabilities

CVE-2011-4114

Published: Jan 13, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.3 LOW
AV:L/AC:M/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The par_mktmpdir function in the PAR::Packer module before 1.012 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program. NOTE: a similar vulnerability was reported for PAR, but this has been assigned a different CVE identifier.

Affected Software

NameVendorStart VersionEnd Version
Par-packer_moduleRoderich_schupp*1.011 (including)
Par-packer_moduleRoderich_schupp0.63 (including)0.63 (including)
Par-packer_moduleRoderich_schupp0.64 (including)0.64 (including)
Par-packer_moduleRoderich_schupp0.65 (including)0.65 (including)
Par-packer_moduleRoderich_schupp0.66 (including)0.66 (including)
Par-packer_moduleRoderich_schupp0.67 (including)0.67 (including)
Par-packer_moduleRoderich_schupp0.68 (including)0.68 (including)
Par-packer_moduleRoderich_schupp0.69 (including)0.69 (including)
Par-packer_moduleRoderich_schupp0.70 (including)0.70 (including)
Par-packer_moduleRoderich_schupp0.71 (including)0.71 (including)
Par-packer_moduleRoderich_schupp0.72 (including)0.72 (including)
Par-packer_moduleRoderich_schupp0.73 (including)0.73 (including)
Par-packer_moduleRoderich_schupp0.74 (including)0.74 (including)
Par-packer_moduleRoderich_schupp0.75 (including)0.75 (including)
Par-packer_moduleRoderich_schupp0.76 (including)0.76 (including)
Par-packer_moduleRoderich_schupp0.77 (including)0.77 (including)
Par-packer_moduleRoderich_schupp0.78 (including)0.78 (including)
Par-packer_moduleRoderich_schupp0.79 (including)0.79 (including)
Par-packer_moduleRoderich_schupp0.80 (including)0.80 (including)
Par-packer_moduleRoderich_schupp0.81 (including)0.81 (including)
Par-packer_moduleRoderich_schupp0.82 (including)0.82 (including)
Par-packer_moduleRoderich_schupp0.83 (including)0.83 (including)
Par-packer_moduleRoderich_schupp0.85 (including)0.85 (including)
Par-packer_moduleRoderich_schupp0.86 (including)0.86 (including)
Par-packer_moduleRoderich_schupp0.87 (including)0.87 (including)
Par-packer_moduleRoderich_schupp0.88 (including)0.88 (including)
Par-packer_moduleRoderich_schupp0.89 (including)0.89 (including)
Par-packer_moduleRoderich_schupp0.90 (including)0.90 (including)
Par-packer_moduleRoderich_schupp0.91 (including)0.91 (including)
Par-packer_moduleRoderich_schupp0.92 (including)0.92 (including)
Par-packer_moduleRoderich_schupp0.93 (including)0.93 (including)
Par-packer_moduleRoderich_schupp0.94 (including)0.94 (including)
Par-packer_moduleRoderich_schupp0.941 (including)0.941 (including)
Par-packer_moduleRoderich_schupp0.942 (including)0.942 (including)
Par-packer_moduleRoderich_schupp0.951 (including)0.951 (including)
Par-packer_moduleRoderich_schupp0.952 (including)0.952 (including)
Par-packer_moduleRoderich_schupp0.953 (including)0.953 (including)
Par-packer_moduleRoderich_schupp0.954 (including)0.954 (including)
Par-packer_moduleRoderich_schupp0.955 (including)0.955 (including)
Par-packer_moduleRoderich_schupp0.956 (including)0.956 (including)
Par-packer_moduleRoderich_schupp0.957 (including)0.957 (including)
Par-packer_moduleRoderich_schupp0.958 (including)0.958 (including)
Par-packer_moduleRoderich_schupp0.959 (including)0.959 (including)
Par-packer_moduleRoderich_schupp0.960 (including)0.960 (including)
Par-packer_moduleRoderich_schupp0.970 (including)0.970 (including)
Par-packer_moduleRoderich_schupp0.973 (including)0.973 (including)
Par-packer_moduleRoderich_schupp0.975 (including)0.975 (including)
Par-packer_moduleRoderich_schupp0.976 (including)0.976 (including)
Par-packer_moduleRoderich_schupp0.977 (including)0.977 (including)
Par-packer_moduleRoderich_schupp0.978 (including)0.978 (including)
Par-packer_moduleRoderich_schupp0.979 (including)0.979 (including)
Par-packer_moduleRoderich_schupp0.980 (including)0.980 (including)
Par-packer_moduleRoderich_schupp0.981 (including)0.981 (including)
Par-packer_moduleRoderich_schupp0.982 (including)0.982 (including)
Par-packer_moduleRoderich_schupp0.991 (including)0.991 (including)
Par-packer_moduleRoderich_schupp0.992_01 (including)0.992_01 (including)
Par-packer_moduleRoderich_schupp0.992_02 (including)0.992_02 (including)
Par-packer_moduleRoderich_schupp0.992_03 (including)0.992_03 (including)
Par-packer_moduleRoderich_schupp0.992_04 (including)0.992_04 (including)
Par-packer_moduleRoderich_schupp0.992_05 (including)0.992_05 (including)
Par-packer_moduleRoderich_schupp0.992_06 (including)0.992_06 (including)
Par-packer_moduleRoderich_schupp1.000 (including)1.000 (including)
Par-packer_moduleRoderich_schupp1.001 (including)1.001 (including)
Par-packer_moduleRoderich_schupp1.002 (including)1.002 (including)
Par-packer_moduleRoderich_schupp1.003 (including)1.003 (including)
Par-packer_moduleRoderich_schupp1.004 (including)1.004 (including)
Par-packer_moduleRoderich_schupp1.005 (including)1.005 (including)
Par-packer_moduleRoderich_schupp1.006 (including)1.006 (including)
Par-packer_moduleRoderich_schupp1.007 (including)1.007 (including)
Par-packer_moduleRoderich_schupp1.008 (including)1.008 (including)
Par-packer_moduleRoderich_schupp1.009 (including)1.009 (including)
Par-packer_moduleRoderich_schupp1.010 (including)1.010 (including)
Libpar-packer-perlUbuntuhardy*
Libpar-packer-perlUbuntulucid*
Libpar-packer-perlUbuntumaverick*
Libpar-packer-perlUbuntunatty*
Libpar-packer-perlUbuntuoneiric*
Libpar-packer-perlUbuntuupstream*

References