Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Perl SuidPerl Multiple Local Vulnerabilities

SuidPerl is reported prone to multiple vulnerabilities. The following individual issues are reported:

- the 'PERLIO_DEBUG' SuidPerl environment variable may be employed to corrupt arbitrary files. A local unprivileged attacker may exploit this vulnerability to corrupt arbitrary files with superuser privileges. This may ultimately lead to a denial of service for legitimate users or to privilege escalation.

- SuidPerl is prone to a local buffer-overflow vulnerability as well. A local attacker may exploit this buffer-overflow vulnerability to gain superuser privileges. This issue is also exploited through the 'PERLIO_DEBUG' variable.







 

Privacy Statement
Copyright 2009, SecurityFocus