First published: Fri Dec 31 1999(Updated: )
Perl 5.004_04 and earlier follows symbolic links when running with the -e option, which allows local users to overwrite arbitrary files via a symlink attack on the /tmp/perl-eaXXXXX file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Perl | <=5.4.4 | |
Perl | <=5.004_04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1386 is classified as a medium severity vulnerability due to its potential for local privilege escalation.
To fix CVE-1999-1386, upgrade to Perl version 5.004_05 or later, which addresses the symbolic link following issue.
Users running Perl versions 5.004_04 and earlier on systems that allow local users to create symbolic links are affected by CVE-1999-1386.
CVE-1999-1386 can enable local users to perform symlink attacks, potentially allowing them to overwrite arbitrary files.
While CVE-1999-1386 refers to an older vulnerability, it remains relevant for legacy systems still running affected versions of Perl.