CVE-1999-1386

Perl 5.004_04 and earlier follows symbolic links when running with the -e option, which allows local users to overwrite arbitrary files via a symlink attack on the /tmp/perl-eaXXXXX file.
Configurations

Configuration 1 (hide)

cpe:2.3:a:perl:perl:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 1999-12-31 05:00

Updated : 2024-01-26 16:54


NVD link : CVE-1999-1386

Mitre link : CVE-1999-1386

CVE.ORG link : CVE-1999-1386


JSON object : View

Products Affected

perl

  • perl
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')