Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2008-2827Race Condition in Perl

CWE-362Race Condition18 documents7 sources
Severity
6.9MEDIUMNVD
NVD4.6OSV2.6
EPSS
0.1%
top 72.25%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJun 23
Latest updateMay 14

Description

The rmtree function in lib/File/Path.pm in Perl 5.10 does not properly check permissions before performing a chmod, which allows local users to modify the permissions of arbitrary files via a symlink attack, a different vulnerability than CVE-2005-0448 and CVE-2004-0452.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages4 packages

NVDperl/file\
debiandebian/perl< perl 5.10.0-18 (bookworm)+1
Debianperl/perl< 5.10.0-18+7
NVDperl/perl5.10

🔴Vulnerability Details

6
GHSA
GHSA-4m3f-gxf5-6jm9: Race condition in the rmtree function in File::Path 12022-05-14
GHSA
GHSA-8vc4-5x78-9hxf: Race condition in the rmtree function in File::Path 12022-05-14
GHSA
GHSA-h567-wg66-2v4f: The rmtree function in lib/File/Path2022-05-01
OSV
CVE-2008-5302: Race condition in the rmtree function in File::Path 12008-12-01
OSV
CVE-2008-5303: Race condition in the rmtree function in File::Path 12008-12-01

💥Exploits & PoCs

1
Exploit-DB
Perl - 'rmtree()' Function Local Insecure Permissions2008-06-23

📋Vendor Advisories

6
Red Hat
perl: File:: Path rmtree race condition (CVE-2005-0448) reintroduced after upstream rebase to 5.8.8-12008-11-19
Red Hat
perl: File:: Path rmtree race condition (CVE-2004-0452) reintroduced after upstream rebase to 5.8.8-12008-11-19
Red Hat
perl: insecure use of chmod in rmtree2008-06-20
Debian
CVE-2008-5303: perl - Race condition in the rmtree function in File::Path 1.08 (lib/File/Path.pm) in P...2008
Debian
CVE-2008-2827: perl - The rmtree function in lib/File/Path.pm in Perl 5.10 does not properly check per...2008

💬Community

2
Bugzilla
CVE-2008-5302 perl: File::Path rmtree race condition (CVE-2005-0448) reintroduced after upstream rebase to 5.8.8-12008-11-28
Bugzilla
CVE-2008-2827 perl: insecure use of chmod in rmtree2008-06-24