ECHO-d134-92e0-c60b

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-d134-92e0-c60b.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-d134-92e0-c60b
Upstream
  • GHSA-grqm-6jmc-2h46
Withdrawn
2025-08-03T16:59:07Z
Published
2025-09-15T01:08:40Z
Modified
2026-09-15T03:42:50Z
Summary
It's pretty dodgy to consider this not applicable, because the CVE can easily be exploited. The vulnerability is in the function is_safe(), which when given a path with symlinks can claim a path cannot be accessed by another user falsely. The justification mostly boils down to the function not being supposed to be relied on for security, but for safety. In other words it's to make sure the user doesn't do stupid things, not to protect against attackers. There is extra nuance in that the function claims to do some things and not be exhaustive anyway, but it's documentation does not mention it cannot follow symlinks. There is no fix upstream or any intention of fixing it, and the fix would almost certainly be a documentation change. Justification: https://seclists.org/oss-sec/2011/q4/234 Bug report and exploit: https://rt.cpan.org/Public/Bug/Display.html?id=69106 Vulnerable code: https://github.com/Perl/perl5/blob/blead/cpan/File-Temp/lib/File/Temp.pm CVE: https://security-tracker.debian.org/tracker/CVE-2011-4116
Details
References

Affected packages

Echo / perl

Package

Name
perl
Purl
pkg:deb/echo/perl

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.36.0-7+deb12u1

Database specific

source
"https://advisory.echohq.com/osv/ECHO-d134-92e0-c60b.json"