CVE-2011-5060

UnknownEPSS 0.31%

Last modified

CVE-2011-5060 is a vulnerability of currently unknown severity. The par_mktmpdir function in the PAR module before 1.003 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program, a different vulnerability in a different package than CVE-2011-4114.. EPSS estimates a 0.31% chance of exploitation in the next 30 days.

Description

The par_mktmpdir function in the PAR module before 1.003 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program, a different vulnerability in a different package than CVE-2011-4114.

Metrics

EPSS Probability
0.31%

22.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Roderich SchuppPar-Packer Module<= 1.002
Roderich SchuppPar-Packer Module0.63
Roderich SchuppPar-Packer Module0.64
Roderich SchuppPar-Packer Module0.65
Roderich SchuppPar-Packer Module0.66
Roderich SchuppPar-Packer Module0.67
Roderich SchuppPar-Packer Module0.68
Roderich SchuppPar-Packer Module0.69
Roderich SchuppPar-Packer Module0.70
Roderich SchuppPar-Packer Module0.71
Roderich SchuppPar-Packer Module0.72
Roderich SchuppPar-Packer Module0.73
Roderich SchuppPar-Packer Module0.74
Roderich SchuppPar-Packer Module0.75
Roderich SchuppPar-Packer Module0.76
Roderich SchuppPar-Packer Module0.77
Roderich SchuppPar-Packer Module0.78
Roderich SchuppPar-Packer Module0.79
Roderich SchuppPar-Packer Module0.80
Roderich SchuppPar-Packer Module0.81
Roderich SchuppPar-Packer Module0.82
Roderich SchuppPar-Packer Module0.83
Roderich SchuppPar-Packer Module0.85
Roderich SchuppPar-Packer Module0.86
Roderich SchuppPar-Packer Module0.87
Roderich SchuppPar-Packer Module0.88
Roderich SchuppPar-Packer Module0.89
Roderich SchuppPar-Packer Module0.90
Roderich SchuppPar-Packer Module0.91
Roderich SchuppPar-Packer Module0.92
Roderich SchuppPar-Packer Module0.93
Roderich SchuppPar-Packer Module0.94
Roderich SchuppPar-Packer Module0.941
Roderich SchuppPar-Packer Module0.942
Roderich SchuppPar-Packer Module0.951
Roderich SchuppPar-Packer Module0.952
Roderich SchuppPar-Packer Module0.953
Roderich SchuppPar-Packer Module0.954
Roderich SchuppPar-Packer Module0.955
Roderich SchuppPar-Packer Module0.956
Roderich SchuppPar-Packer Module0.957
Roderich SchuppPar-Packer Module0.958
Roderich SchuppPar-Packer Module0.959
Roderich SchuppPar-Packer Module0.960
Roderich SchuppPar-Packer Module0.970
Roderich SchuppPar-Packer Module0.973
Roderich SchuppPar-Packer Module0.975
Roderich SchuppPar-Packer Module0.976
Roderich SchuppPar-Packer Module0.977
Roderich SchuppPar-Packer Module0.978

Showing 50 of 63 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2011-5060?
The par_mktmpdir function in the PAR module before 1.003 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program, a different vulnerability in a different package than CVE-2011-4114.
How severe is CVE-2011-5060?
Severity scoring for CVE-2011-5060 is pending analysis. The EPSS model estimates a 0.31% probability of exploitation in the next 30 days.
How do I fix CVE-2011-5060?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2011-5060?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST