The cPanel Security Team reported a time of check to time of use (TOCTTOU) race condition flaw in File::Path, a core module from Perl to create or remove directory trees. An attacker can take advantage of this flaw to set the mode on an attacker-chosen file to an attacker-chosen . Hash: SHA256 Package : perl Version : 5.14.2-21+deb7u5 CVE ID : CVE-2017-6512 Debian Bug : 863870 The cPanel Security Team reported a time of check to time of use (TOCTTOU) race condition flaw in File::Path, a core module from Perl to create or remove directory trees. An attacker can take advantage of this flaw to set the mode on an attacker-chosen file to an attacker-chosen value. For Debian 7 "Wheezy", these problems have been fixed in version 5.14.2-21+deb7u5. We recommend that you upgrade your perl packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A recent update for Perl on Debian mitigates a significant TOCTOU vulnerability, reinforcing system defenses against certain forms of exploitation.. Debian, Perl, TOCTTOU, Security Update, cPanel. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.