CVE-2004-0452

Publication date 21 December 2004

Last updated 24 July 2024


Ubuntu priority

Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for the world, which allows local users to delete arbitrary files and directories, and possibly read files and directories, via a symlink attack.

Status

Package Ubuntu Release Status
perl 7.04 feisty
Fixed 5.8.7-10ubuntu1
6.10 edgy
Fixed 5.8.7-10ubuntu1
6.06 LTS dapper
Fixed 5.8.7-10ubuntu1

References

Related Ubuntu Security Notices (USN)

    • USN-44-1
    • perl information leak
    • 21 December 2004

Other references