CVE-2011-4363: Low severity frii proc vulnerability
Published Oct 7, 2012
·Updated
ProcessTable.pm in the Proc::ProcessTable module 0.45 for Perl, when TTY information caching is enabled, allows local users to overwrite arbitrary files via a symlink attack on /tmp/TTYDEVS.
Affected Software
2 affected components
Frii Proc\=\-processtable
Perl Perl
Event History
Oct 7, 2012
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
09:55 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-4363?
CVE-2011-4363 is rated as a high-severity vulnerability due to its potential for local users to exploit the symlink attack.
2
How do I fix CVE-2011-4363?
To mitigate CVE-2011-4363, disable TTY information caching or upgrade the Proc::ProcessTable module to a newer, patched version.
3
Who is affected by CVE-2011-4363?
Local users on systems running Proc::ProcessTable version 0.45 with TTY information caching enabled are affected by CVE-2011-4363.
4
What type of attack is associated with CVE-2011-4363?
CVE-2011-4363 is associated with a symlink attack that can lead to arbitrary file overwriting.
5
What software versions are vulnerable to CVE-2011-4363?
Proc::ProcessTable version 0.45 is the specific version vulnerable to CVE-2011-4363.