漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files
Vulnerability Description
File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files.
When the file to be rotated is a symbolic link to a missing file, and the touch option is enabled, then the rotate method assumes that the file is absent (since the existence check is against the target), and does not rotate it. But it touches the file, which creates the target.
An attacker that has the ability to create the symlink can use this to create an arbitrary file with permissions of the process rotating the files (which may be different from the process that normally writes to the log file that is being rotated).
Note that the touch option is disabled by default.
CVSS Information
N/A
Vulnerability Type
在文件访问前对链接解析不恰当(链接跟随)
Vulnerability Title
RRWO File::Rotate::Simple 后置链接漏洞
Vulnerability Description
RRWO File::Rotate::Simple是RRWO个人开发者开源的一个简单的文件轮转模块。 RRWO File::Rotate::Simple 0.4.0之前版本存在后置链接漏洞,该漏洞源于处理悬空符号链接时存在问题,可能导致攻击者以旋转文件的进程权限创建任意文件。
CVSS Information
N/A
Vulnerability Type
N/A