CVE-2005-0448
| Name | CVE-2005-0448 |
| Source | CVE (at NVD; RH) |
| Description | Race condition in the rmtree function in File::Path.pm in Perl before 5.8.4 allows local users to create arbitrary setuid binaries in the tree being deleted, a different vulnerability than CVE-2004-0452. |
| References | DSA-1678-1, DSA-696-1 |
| NVD severity | low (attack range: local) |
| Debian/oldstable | not vulnerable. |
| Debian/stable | not vulnerable. |
| Debian/testing | not vulnerable. |
| Debian/unstable | not vulnerable. |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| perl (PTS) | lenny | 5.10.0-19lenny3 | fixed |
| lenny (security) | 5.10.0-19lenny5 | fixed |
| squeeze (security) | 5.10.1-17squeeze2 | fixed |
| squeeze | 5.10.1-17squeeze3 | fixed |
| wheezy | 5.14.2-6 | fixed |
| sid | 5.14.2-7 | fixed |
| experimental | 5.14.2-8 | fixed |
The information above is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|
| perl | source | (unstable) | 5.8.4-7 | low | | |
| perl | source | etch | 5.8.8-7etch5 | low | DSA-1678-1 | |
| perl | source | woody | 5.6.1-8.9 | low | DSA-696-1 | |
Home - Testing Security Team - Debian Security - Imprint