CVE-2005-0077
published 2005-05-02CVE-2005-0077: The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.
PriorityP48low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.41%
33.4th percentile
The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libdbi-perl | < libdbi-perl 1.46-6 (bookworm) | libdbi-perl 1.46-6 (bookworm) |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| ubuntu | ubuntu_linux | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Perl DBI module vulnerability
vendor_ubuntu·2005-01-26
CVE-2005-0077 Perl DBI module vulnerability
Title: Perl DBI module vulnerability
Summary: Perl DBI module vulnerability
Javier Fernández-Sanguino Peña from the Debian Security Audit Project
discovered that the module DBI::ProxyServer in Perl's DBI library
created a PID file in an insecure manner. This could allow a symbolic
link attack to create or overwrite arbitrary files with the privileges
of the user invoking a program using this module (like 'dbiproxy').
Now the module does not create a such a PID file by default.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
security flaw
vendor_redhat·2005-01-25·CVSS 2.1
CVE-2005-0077 [LOW] security flaw
security flaw
The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.
Debian
CVE-2005-0077: libdbi-perl - The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary...
vendor_debian·2005·CVSS 2.1
CVE-2005-0077 [LOW] CVE-2005-0077: libdbi-perl - The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary...
The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.
Scope: local
bookworm: resolved (fixed in 1.46-6)
bullseye: resolved (fixed in 1.46-6)
forky: resolved (fixed in 1.46-6)
sid: resolved (fixed in 1.46-6)
trixie: resolved (fixed in 1.46-6)
GHSA
GHSA-wpm8-xxrr-cfh8: The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file
ghsa_unreviewed·2022-05-01
CVE-2005-0077 [LOW] GHSA-wpm8-xxrr-cfh8: The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file
The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.
OSV
CVE-2005-0077: The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file
osv·2005-05-02·CVSS 2.1
CVE-2005-0077 [LOW] CVE-2005-0077: The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file
The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.
No detection rules found.
No public exploits indexed.
http://marc.info/?l=bugtraq&m=110667936707597&w=2http://secunia.com/advisories/14015http://secunia.com/advisories/14050http://securitytracker.com/id?1013007http://www.debian.org/security/2005/dsa-658http://www.gentoo.org/security/en/glsa/glsa-200501-38.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:030http://www.redhat.com/support/errata/RHSA-2005-072.htmlhttp://www.securityfocus.com/archive/1/426530/30/6600/threadedhttp://www.securityfocus.com/bid/12360https://exchange.xforce.ibmcloud.com/vulnerabilities/19068https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10552http://marc.info/?l=bugtraq&m=110667936707597&w=2http://secunia.com/advisories/14015http://secunia.com/advisories/14050http://securitytracker.com/id?1013007http://www.debian.org/security/2005/dsa-658http://www.gentoo.org/security/en/glsa/glsa-200501-38.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:030http://www.redhat.com/support/errata/RHSA-2005-072.htmlhttp://www.securityfocus.com/archive/1/426530/30/6600/threadedhttp://www.securityfocus.com/bid/12360https://exchange.xforce.ibmcloud.com/vulnerabilities/19068https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10552
2005-05-02
Published