CVE-2005-0448

16 documents8 sources
Severity
1.2LOW
EPSS
0.1%
top 74.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 2
Latest updateMay 3

Description

Race condition in the rmtree function in File::Path.pm in Perl before 5.8.4 allows local users to create arbitrary setuid binaries in the tree being deleted, a different vulnerability than CVE-2004-0452.

CVSS vector

AV:L/AC:H/C:N/I:P/A:NExploitability: 1.9 | Impact: 2.9

Affected Packages2 packages

Debianperl< 5.8.4-7+3
NVDlarry_wall/perl4 versions+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-2jcf-pv2j-gqvq: Race condition in the rmtree function in File::Path2022-05-03
OSV
CVE-2005-0448: Race condition in the rmtree function in File::Path2005-05-02
CVEList
CVE-2005-0448: Race condition in the rmtree function in File::Path2005-03-12

📋Vendor Advisories

6
Red Hat
perl: File:: Path rmtree race condition (CVE-2005-0448) reintroduced after upstream rebase to 5.8.8-12008-11-19
Red Hat
perl: File:: Path rmtree race condition (CVE-2004-0452) reintroduced after upstream rebase to 5.8.8-12008-11-19
Red Hat
perl: insecure use of chmod in rmtree2008-06-20
Red Hat
security flaw2005-03-09
Ubuntu
Perl vulnerability2005-03-09

💬Community

5
Bugzilla
CVE-2005-0448 security flaw2018-08-16
Bugzilla
CVE-2008-5302 perl: File::Path rmtree race condition (CVE-2005-0448) reintroduced after upstream rebase to 5.8.8-12008-11-28
Bugzilla
CVE-2008-2827 perl: insecure use of chmod in rmtree2008-06-24
Bugzilla
CVE-2005-0448 perl File::Path.pm rmtree race condition2005-06-20
Bugzilla
CVE-2005-0448 perl File::Path.pm rmtree race condition2005-06-20
CVE-2005-0448 (LOW CVSS 1.2) | Race condition in the rmtree functi | cvebase.io