Description
The rmtree function in lib/File/Path.pm in Perl 5.10 does not properly check permissions before performing a chmod, which allows local users to modify the permissions of arbitrary files via a symlink attack, a different vulnerability than CVE-2005-0448 and CVE-2004-0452.
Remediation
References
Related Vulnerabilities
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2009-2854)
WordPress Plugin Testimonial Slider Cross-Site Scripting (1.2.1)
Oracle Application Server Other Vulnerability (CVE-2002-0947)
Liferay DXP Missing Authorization Vulnerability (CVE-2025-62256)
WordPress Plugin Wow Forms-create any form with custom style SQL Injection (3.1.3)