CVE-2012-2451

N/A Unknown
Published: June 27, 2012 Modified: April 29, 2026
View on NVD

Description

The Config::IniFiles module before 2.71 for Perl creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack. NOTE: some of these details are obtained from third party information. NOTE: it has been reported that this might only be exploitable by writing in the same directory as the .ini file. If this is the case, then this issue might not cross privilege boundaries.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/48990
Source: cve@mitre.org
Vendor Advisory
http://www.osvdb.org/81671
Source: cve@mitre.org
http://secunia.com/advisories/48990
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.openwall.com/lists/oss-security/2012/05/02/6
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/81671
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/53361
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/USN-1543-1
Source: af854a3a-2127-422b-91ae-364da2661108
https://bitbucket.org/shlomif/perl-config-inifiles/changeset/a08fa26f4f59
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit Patch
https://bugzilla.redhat.com/show_bug.cgi?id=818386
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/75328
Source: af854a3a-2127-422b-91ae-364da2661108

22 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
0.5%
39th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

shlomi_fish