The Config::IniFiles module before 2.71 for Perl creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack. NOTE: some of these details are obtained from third party information. NOTE: it has been reported that this might only be exploitable by writing in the same directory as the .ini file. If this is the case, then this issue might not cross privilege boundaries.
CVSS Details
- CVSS 3.1 Base Score: 4.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libconfig-inifiles-perl | Jul 30, 2024 | Jun 27, 2012 |
| Freebsd | — | Upgrade p5-Config-IniFiles | Dec 10, 2025 | May 7, 2012 |
| Gentoo Linux | — | Upgrade dev-perl/Config-IniFiles. | Oct 30, 2017 | Jun 27, 2012 |
| Suse | — | Upgrade perl-Config-IniFiles | Aug 9, 2024 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libconfig-inifiles-perl | Nov 8, 2024 | Jun 27, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub