perl: insecure use of chmod in rmtree
Published Jun 23, 2008
4.6
MEDIUMCVSS 2.0
EPSS 0.84%
Description
The rmtree function in lib/File/Path.pm in Perl 5.10 does not properly check permissions before performing a chmod, which allows local users to modify the permissions of arbitrary files via a symlink attack, a different vulnerability than CVE-2005-0448 and CVE-2004-0452.
Affected products
Remediation
Red Hat statement
Not vulnerable. This issue did not affect the versions of perl as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5, Red Hat Application Stack 1, or Solaris versions of Red Hat Directory Server 7.1 and 8, Certificate System 7.x.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.84% (0.00843) | 56.40th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.85% (0.00850) | 53.21th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.09% (0.00086) | 22.52th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00043) | 11.55th | v3 (v2023.03.01) |
| Jun 12, 2024 | 0.04% (0.00043) | 9.63th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00043) | 7.62th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.22% (0.03220) | 84.21th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.22% (0.03220) | 82.61th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.22% (0.03220) | 65.30th | v2 (v2022.01.01) |
References (15)
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=487319 x_refsource_CONFIRMExploit
- http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html vendor-advisoryx_refsource_SUSE
- http://rt.cpan.org/Public/Bug/Display.html?id=36982 x_refsource_MISCExploit
- http://secunia.com/advisories/30790 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30837 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/31687 third-party-advisoryx_refsource_SECUNIA
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:165 vendor-advisoryx_refsource_MANDRIVA
- http://www.securityfocus.com/bid/29902 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1020373 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/security/cve/CVE-2008-2827 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=452635 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43308 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2008-2827
- https://www.cve.org/CVERecord?id=CVE-2008-2827
- https://www.redhat.com/archives/fedora-package-announce/2008-June/msg01025.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.