This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Roderich Schupp First view 2012-01-13
Product Par-Packer Module Last view 2012-01-13
Version 0.81 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:roderich_schupp:par-packer_module

Activity : Overall

Related : CVE

  Date Alert Description
3.3 2012-01-13 CVE-2011-5060

The par_mktmpdir function in the PAR module before 1.003 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program, a different vulnerability in a different package than CVE-2011-4114.

3.3 2012-01-13 CVE-2011-4114

The par_mktmpdir function in the PAR::Packer module before 1.012 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program. NOTE: a similar vulnerability was reported for PAR, but this has been assigned a different CVE identifier.

CWE : Common Weakness Enumeration

%idName
100% (2) CWE-264 Permissions, Privileges, and Access Controls

Open Source Vulnerability Database (OSVDB)

id Description
77463 Multiple PAR Module for Perl Temporary File Symlink Arbitrary File Overwrite

OpenVAS Exploits

id Description
2012-04-02 Name : Fedora Update for perl-PAR-Packer FEDORA-2011-16856
File : nvt/gb_fedora_2011_16856_perl-PAR-Packer_fc16.nasl
2012-04-02 Name : Fedora Update for perl-PAR FEDORA-2011-16856
File : nvt/gb_fedora_2011_16856_perl-PAR_fc16.nasl
2012-01-17 Name : Strawberry Perl Modules Multiple Vulnerabilities (Windows)
File : nvt/gb_perl_modules_mult_vuln_win.nasl
2011-12-23 Name : Fedora Update for perl-PAR-Packer FEDORA-2011-16859
File : nvt/gb_fedora_2011_16859_perl-PAR-Packer_fc15.nasl
2011-12-23 Name : Fedora Update for perl-PAR FEDORA-2011-16859
File : nvt/gb_fedora_2011_16859_perl-PAR_fc15.nasl

Nessus® Vulnerability Scanner

id Description
2011-12-22 Name: The remote Fedora host is missing one or more security updates.
File: fedora_2011-16856.nasl - Type: ACT_GATHER_INFO
2011-12-22 Name: The remote Fedora host is missing one or more security updates.
File: fedora_2011-16859.nasl - Type: ACT_GATHER_INFO