Race condition in the rmtree and remove_tree functions allows attackers to set the mode on arbitrary files via vectors involving directory-permission loosening logic.
References:CPANSA-File-Path-2017-01
Race condition in the rmtree and remove_tree functions allows attackers to set the mode on arbitrary files via vectors involving directory-permission loosening logic.
| Affected Packages | Affected Versions | Fixed Versions | |
|---|---|---|---|
| cpan:File-Path | < 2.13 | 2.13 | |
Affected Version RangesAll affected versionsAll unaffected versions |
|||
Potentially Affected Packages
These packages share the same source repository and may be affected by this vulnerability, but are not listed in the advisory.
| Package | Ecosystem | Latest Version | Classification |
|---|---|---|---|
| perl-file-path | conda | Repackage |