CVE-2008-5302
published 2008-12-01CVE-2008-5302: Race condition in the rmtree function in File::Path 1.08 and 2.07 (lib/File/Path.pm) in Perl 5.8.8 and 5.10.0 allows local users to create arbitrary setuid…
PriorityP421medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.33%
25.6th percentile
Race condition in the rmtree function in File::Path 1.08 and 2.07 (lib/File/Path.pm) in Perl 5.8.8 and 5.10.0 allows local users to create arbitrary setuid binaries via a symlink attack, a different vulnerability than CVE-2005-0448, CVE-2004-0452, and CVE-2008-2827. NOTE: this is a regression error related to CVE-2005-0448. It is different from CVE-2008-5303 due to affected versions.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | perl | < perl 5.10.0-18 (bookworm) | perl 5.10.0-18 (bookworm) |
| perl | file | — | — |
| perl | perl | >= 0 < 5.10.0-18 | 5.10.0-18 |
| perl | perl | >= 0 < 5.10.0-18 | 5.10.0-18 |
| perl | perl | >= 0 < 5.10.0-18 | 5.10.0-18 |
| perl | perl | >= 0 < 5.10.0-18 | 5.10.0-18 |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv2.6LOW
vendor_ubuntu6.8MEDIUM
vendor_debian2.6LOW
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Perl regression
vendor_ubuntu·2009-01-15·CVSS 6.8
[MEDIUM] Perl regression
Title: Perl regression
Summary: Perl regression
USN-700-1 fixed vulnerabilities in Perl. Due to problems with the Ubuntu
8.04 build, some Perl .ph files were missing from the resulting update.
This update fixes the problem. We apologize for the inconvenience.
Original advisory details:
Jonathan Smith discovered that the Archive::Tar Perl module did not
correctly handle symlinks when extracting archives. If a user or
automated system were tricked into opening a specially crafted tar file,
a remote attacker could over-write arbitrary files. (CVE-2007-4829)
Tavis Ormandy and Will Drewry discovered that Perl did not correctly
handle certain utf8 characters in regular expressions. If a user or
automated system were tricked into using a specially crafted expression,
a remote attacker could
Ubuntu
Perl vulnerabilities
vendor_ubuntu·2008-12-24·CVSS 6.8
CVE-2007-4829 [MEDIUM] Perl vulnerabilities
Title: Perl vulnerabilities
Summary: Perl vulnerabilities
Jonathan Smith discovered that the Archive::Tar Perl module did not
correctly handle symlinks when extracting archives. If a user or
automated system were tricked into opening a specially crafted tar file,
a remote attacker could over-write arbitrary files. (CVE-2007-4829)
Tavis Ormandy and Will Drewry discovered that Perl did not correctly
handle certain utf8 characters in regular expressions. If a user or
automated system were tricked into using a specially crafted expression,
a remote attacker could crash the application, leading to a denial
of service. Ubuntu 8.10 was not affected by this issue. (CVE-2008-1927)
A race condition was discovered in the File::Path Perl module's rmtree
function. If a local attacker successfully r
Red Hat
perl: File:: Path rmtree race condition (CVE-2005-0448) reintroduced after upstream rebase to 5.8.8-1
vendor_redhat·2008-11-19·CVSS 2.6
CVE-2008-5302 [LOW] perl: File:: Path rmtree race condition (CVE-2005-0448) reintroduced after upstream rebase to 5.8.8-1
perl: File:: Path rmtree race condition (CVE-2005-0448) reintroduced after upstream rebase to 5.8.8-1
Race condition in the rmtree function in File::Path 1.08 and 2.07 (lib/File/Path.pm) in Perl 5.8.8 and 5.10.0 allows local users to create arbitrary setuid binaries via a symlink attack, a different vulnerability than CVE-2005-0448, CVE-2004-0452, and CVE-2008-2827. NOTE: this is a regression error related to CVE-2005-0448. It is different from CVE-2008-5303 due to affected versions.
Red Hat
perl: File:: Path rmtree race condition (CVE-2004-0452) reintroduced after upstream rebase to 5.8.8-1
vendor_redhat·2008-11-19·CVSS 2.6
CVE-2008-5303 [LOW] perl: File:: Path rmtree race condition (CVE-2004-0452) reintroduced after upstream rebase to 5.8.8-1
perl: File:: Path rmtree race condition (CVE-2004-0452) reintroduced after upstream rebase to 5.8.8-1
Race condition in the rmtree function in File::Path 1.08 (lib/File/Path.pm) in Perl 5.8.8 allows local users to to delete arbitrary files via a symlink attack, a different vulnerability than CVE-2005-0448, CVE-2004-0452, and CVE-2008-2827. NOTE: this is a regression error related to CVE-2005-0448. It is different from CVE-2008-5302 due to affected versions.
Debian
CVE-2008-5303: perl - Race condition in the rmtree function in File::Path 1.08 (lib/File/Path.pm) in P...
vendor_debian·2008·CVSS 2.6
CVE-2008-5303 [LOW] CVE-2008-5303: perl - Race condition in the rmtree function in File::Path 1.08 (lib/File/Path.pm) in P...
Race condition in the rmtree function in File::Path 1.08 (lib/File/Path.pm) in Perl 5.8.8 allows local users to to delete arbitrary files via a symlink attack, a different vulnerability than CVE-2005-0448, CVE-2004-0452, and CVE-2008-2827. NOTE: this is a regression error related to CVE-2005-0448. It is different from CVE-2008-5302 due to affected versions.
Scope: local
bookworm: resolved (fixed in 5.10.0-18)
bullseye: resolved (fixed in 5.10.0-18)
forky: resolved (fixed in 5.10.0-18)
sid: resolved (fixed in 5.10.0-18)
trixie: resolved (fixed in 5.10.0-18)
Debian
CVE-2008-5302: perl - Race condition in the rmtree function in File::Path 1.08 and 2.07 (lib/File/Path...
vendor_debian·2008·CVSS 2.6
CVE-2008-5302 [LOW] CVE-2008-5302: perl - Race condition in the rmtree function in File::Path 1.08 and 2.07 (lib/File/Path...
Race condition in the rmtree function in File::Path 1.08 and 2.07 (lib/File/Path.pm) in Perl 5.8.8 and 5.10.0 allows local users to create arbitrary setuid binaries via a symlink attack, a different vulnerability than CVE-2005-0448, CVE-2004-0452, and CVE-2008-2827. NOTE: this is a regression error related to CVE-2005-0448. It is different from CVE-2008-5303 due to affected versions.
Scope: local
bookworm: resolved (fixed in 5.10.0-18)
bullseye: resolved (fixed in 5.10.0-18)
forky: resolved (fixed in 5.10.0-18)
sid: resolved (fixed in 5.10.0-18)
trixie: resolved (fixed in 5.10.0-18)
GHSA
GHSA-4m3f-gxf5-6jm9: Race condition in the rmtree function in File::Path 1
ghsa_unreviewed·2022-05-14·CVSS 2.6
CVE-2008-5303 [LOW] CWE-362 GHSA-4m3f-gxf5-6jm9: Race condition in the rmtree function in File::Path 1
Race condition in the rmtree function in File::Path 1.08 (lib/File/Path.pm) in Perl 5.8.8 allows local users to to delete arbitrary files via a symlink attack, a different vulnerability than CVE-2005-0448, CVE-2004-0452, and CVE-2008-2827. NOTE: this is a regression error related to CVE-2005-0448. It is different from CVE-2008-5302 due to affected versions.
GHSA
GHSA-8vc4-5x78-9hxf: Race condition in the rmtree function in File::Path 1
ghsa_unreviewed·2022-05-14·CVSS 2.6
CVE-2008-5302 [LOW] CWE-362 GHSA-8vc4-5x78-9hxf: Race condition in the rmtree function in File::Path 1
Race condition in the rmtree function in File::Path 1.08 and 2.07 (lib/File/Path.pm) in Perl 5.8.8 and 5.10.0 allows local users to create arbitrary setuid binaries via a symlink attack, a different vulnerability than CVE-2005-0448, CVE-2004-0452, and CVE-2008-2827. NOTE: this is a regression error related to CVE-2005-0448. It is different from CVE-2008-5303 due to affected versions.
OSV
CVE-2008-5302: Race condition in the rmtree function in File::Path 1
osv·2008-12-01·CVSS 2.6
CVE-2008-5302 [LOW] CVE-2008-5302: Race condition in the rmtree function in File::Path 1
Race condition in the rmtree function in File::Path 1.08 and 2.07 (lib/File/Path.pm) in Perl 5.8.8 and 5.10.0 allows local users to create arbitrary setuid binaries via a symlink attack, a different vulnerability than CVE-2005-0448, CVE-2004-0452, and CVE-2008-2827. NOTE: this is a regression error related to CVE-2005-0448. It is different from CVE-2008-5303 due to affected versions.
OSV
CVE-2008-5303: Race condition in the rmtree function in File::Path 1
osv·2008-12-01·CVSS 2.6
CVE-2008-5303 [LOW] CVE-2008-5303: Race condition in the rmtree function in File::Path 1
Race condition in the rmtree function in File::Path 1.08 (lib/File/Path.pm) in Perl 5.8.8 allows local users to to delete arbitrary files via a symlink attack, a different vulnerability than CVE-2005-0448, CVE-2004-0452, and CVE-2008-2827. NOTE: this is a regression error related to CVE-2005-0448. It is different from CVE-2008-5302 due to affected versions.
No detection rules found.
No public exploits indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286905http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286922#36http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.htmlhttp://secunia.com/advisories/32980http://secunia.com/advisories/33314http://secunia.com/advisories/40052http://support.apple.com/kb/HT4077http://wiki.rpath.com/Advisories:rPSA-2009-0011http://www.debian.org/security/2008/dsa-1678http://www.gossamer-threads.com/lists/perl/porters/233695#233695http://www.mandriva.com/security/advisories?name=MDVSA-2010:116http://www.openwall.com/lists/oss-security/2008/11/28/2http://www.redhat.com/support/errata/RHSA-2010-0458.htmlhttp://www.securityfocus.com/archive/1/500210/100/0/threadedhttp://www.ubuntu.com/usn/usn-700-1http://www.ubuntu.com/usn/usn-700-2https://exchange.xforce.ibmcloud.com/vulnerabilities/47043https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11076https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6890http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286905http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286922#36http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.htmlhttp://secunia.com/advisories/32980http://secunia.com/advisories/33314http://secunia.com/advisories/40052http://support.apple.com/kb/HT4077http://wiki.rpath.com/Advisories:rPSA-2009-0011http://www.debian.org/security/2008/dsa-1678http://www.gossamer-threads.com/lists/perl/porters/233695#233695http://www.mandriva.com/security/advisories?name=MDVSA-2010:116http://www.openwall.com/lists/oss-security/2008/11/28/2http://www.redhat.com/support/errata/RHSA-2010-0458.htmlhttp://www.securityfocus.com/archive/1/500210/100/0/threadedhttp://www.ubuntu.com/usn/usn-700-1http://www.ubuntu.com/usn/usn-700-2https://exchange.xforce.ibmcloud.com/vulnerabilities/47043https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11076https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6890
2008-12-01
Published