Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files
Vulnerability Description
File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files.
When the file to be rotated is a symbolic link to a missing file, and the touch option is enabled, then the rotate method assumes that the file is absent (since the existence check is against the target), and does not rotate it. But it touches the file, which creates the target.
An attacker that has the ability to create the symlink can use this to create an arbitrary file with permissions of the process rotating the files (which may be different from the process that normally writes to the log file that is being rotated).
Note that the touch option is disabled by default.
CVSS Information
N/A
Vulnerability Type
在文件访问前对链接解析不恰当(链接跟随)
Vulnerability Title
RRWO File::Rotate::Simple 后置链接漏洞
Vulnerability Description
RRWO File::Rotate::Simple是RRWO个人开发者开源的一个简单的文件轮转模块。 RRWO File::Rotate::Simple 0.4.0之前版本存在后置链接漏洞,该漏洞源于处理悬空符号链接时存在问题,可能导致攻击者以旋转文件的进程权限创建任意文件。
CVSS Information
N/A
Vulnerability Type
N/A