Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for the world, which allows local users to delete arbitrary files and directories, and possibly read files and directories, via a symlink attack.
CVSS Details
- CVSS 3.1 Base Score: 4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade perl | Jul 30, 2024 | Dec 21, 2004 |
| Freebsd | — | Upgrade perlUpgrade perl-threaded | Dec 10, 2025 | Jan 21, 2005 |
| Gentoo Linux | — | Upgrade dev-lang/perl.Upgrade dev-perl/DBI. | Oct 30, 2017 | Dec 21, 2004 |
| Oracle Solaris | — | Upgrade runtime/perl-584/extra to version 5.8.4-0.175.1.11.0.3.2 on Solaris 11.1Upgrade runtime/perl-584 to version 5.8.4-0.175.1.11.0.3.2 on Solaris 11.1Upgrade consolidation/osnet/osnet-incorporation to version 0.5.11-0.175.2.0.0.42.2 on Solaris 11.2 | May 29, 2017 | Dec 21, 2004 |
| Suse | — | Upgrade perl-x86Upgrade perl-64bitUpgrade perlUpgrade perl-32bit | Feb 17, 2015 | Dec 21, 2004 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub