CVE-2011-5060
Publication date 13 January 2012
Last updated 24 July 2024
Ubuntu priority
The par_mktmpdir function in the PAR module before 1.003 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program, a different vulnerability in a different package than CVE-2011-4114.
Notes
sbeattie
upstream and debian fixed this issue in libpar-packer-perl and libpar-perl identifying it as CVE-2011-4114; libpar-perl subsequently got split off into this cve.