CVE-2011-4114

NameCVE-2011-4114
DescriptionThe par_mktmpdir function in the PAR::Packer module before 1.012 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program. NOTE: a similar vulnerability was reported for PAR, but this has been assigned a different CVE identifier.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs650706

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libpar-packer-perl (PTS)buster1.047-1fixed
bullseye1.052-1fixed
bookworm1.057-1fixed
trixie1.061-1fixed
sid1.063-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libpar-packer-perlsourcesqueeze1.006-1+squeeze1
libpar-packer-perlsource(unstable)1.012-1650706

Search for package or bug name: Reporting problems