CVE-2008-5302 describes a race condition in the rmtree function within File::Path versions 1.08 and 2.07 in Perl 5.8.8 and 5.10.0. This vulnerability allows a local attacker to create arbitrary setuid binaries through a symlink attack. Rated with a CVSS score of 6.9, it carries high impact for confidentiality, integrity, and availability, with medium attack complexity. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.08CPE matchmatch criteria | cpe:2.3:a:perl:file\:\:path:1.08:*:*:*:*:*:*:* | ||
2.07CPE matchmatch criteria | cpe:2.3:a:perl:file\:\:path:2.07:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.