Description: Multiple vulnerabilities have been reported in Perl, which can be exploited by malicious, local users to perform certain actions on a vulnerable system with escalated privileges.
The vulnerabilities are caused due to various scripts creating temporary files insecurely. This can be exploited via symlink attacks to create or overwrite arbitrary files on the system with the privileges of the user executing a vulnerable script.
Solution: The majority of the vulnerabilities have been fixed in version 5.8.5. http://www.perl.org/
Grant only trusted users access to affected systems.
Provided and/or discovered by: First reported in a Trustix advisory.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.