REDHAT-BUG-1135624: Low severity Perl Clipboard vulnerability
It was reported [1],[2] that the clipedit program as shipped with perl-Clipboard uses temporary files insecurely (based on the PID of the running program). Using symlink attacks, an attacker could cause the deletion of arbitrary files that the user running clipedit has write access to.
[...] 7 my $tmpfilename = "/tmp/clipedit$$"; 8 open my $tmpfile, ">$tmpfilename" or die "Failure to open $tmpfilename: $!"; 9 print $tmpfile $orig; 10 close $tmpfile; [...] 13 system($ed, $tmpfilename); 14 15 open $tmpfile, $tmpfilename or die "Failure to open $tmpfilename: $!"; 16 my $edited = join '', <$tmpfile>; [...] 49 unlink($tmpfilename) or die "Couldn't remove $tmpfilename: $!";
[1] http://seclists.org/oss-sec/2014/q3/467 [2] https://rt.cpan.org/Public/Bug/Display.html?id=98435
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1135624?
The severity of REDHAT-BUG-1135624 is rated as moderate due to the potential for arbitrary file deletion.
How do I fix REDHAT-BUG-1135624?
To fix REDHAT-BUG-1135624, you should update to the latest version of the Perl Clipboard package that includes the security patch.
Who is affected by REDHAT-BUG-1135624?
Users running the clipedit program from the Perl Clipboard package are affected by REDHAT-BUG-1135624.
What kind of attack is possible with REDHAT-BUG-1135624?
A symlink attack is possible with REDHAT-BUG-1135624, allowing an attacker to manipulate temporary files for malicious purposes.
What are the symptoms of exploitation of REDHAT-BUG-1135624?
The symptoms of exploitation of REDHAT-BUG-1135624 may include unexpected file deletions by the clipedit program.