CVE-2014-2277 describes a local privilege escalation vulnerability in perltidy versions 20120701-1 and earlier, specifically within the make_temporary_filename function. This flaw allows local attackers to conduct symlink attacks, potentially leading to sensitive information disclosure or arbitrary file writes due to the insecure use of the tmpnam function. Rated with a CVSS score of 7.1 (HIGH), this vulnerability has a low attack complexity and requires local access, but can result in high confidentiality and integrity impacts. The EPSS score is very low, indicating a minimal likelihood of exploitation. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are also absent, suggesting a lack of widespread attention or exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2012-07-01-1CPE matchmatch criteria | cpe:2.3:a:perltidy_project:perltidy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.