Feed/CVE-2012-2451
CVE-2012-2451LOWCVSS 3.6

CVE-2012-2451

Published Jun 27, 2012·Updated Jun 16, 2026

NVD Description

The Config::IniFiles module before 2.71 for Perl creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack. NOTE: some of these details are obtained from third party information. NOTE: it has been reported that this might only be exploitable by writing in the same directory as the .ini file. If this is the case, then this issue might not cross privilege boundaries.

CVSS Vector

AV:L/AC:L/Au:N/C:N/I:P/A:P

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free