CVE-2011-4114 - CVE House
Back to Database
Status published Low CVE-2011-4114

The par_mktmpdir function in the PAR::Packer module before 1.012 for...

Vulnerability Description

The par_mktmpdir function in the PAR::Packer module before 1.012 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program. NOTE: a similar vulnerability was reported for PAR, but this has been assigned a different CVE identifier.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-4114

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

roderich schupp

View all reports →

Affected Software

par-packer module
Vulnerable Versions:
0, 0.63, 0.64, 0.65, 0.66, 0.67, 0.68, 0.69, 0.70, 0.71, 0.72, 0.73, 0.74, 0.75, 0.76, 0.77, 0.78, 0.79, 0.80, 0.81, 0.82, 0.83, 0.85, 0.86, 0.87, 0.88, 0.89, 0.90, 0.91, 0.92, 0.93, 0.94, 0.941, 0.942, 0.951, 0.952, 0.953, 0.954, 0.955, 0.956, 0.957, 0.958, 0.959, 0.960, 0.970, 0.973, 0.975, 0.976, 0.977, 0.978, 0.979, 0.980, 0.981, 0.982, 0.991, 0.992_01, 0.992_02, 0.992_03, 0.992_04, 0.992_05, 0.992_06, 1.000, 1.001, 1.002, 1.003, 1.004, 1.005, 1.006, 1.007, 1.008, 1.009, 1.010

Timeline

Official Publish: January 13th, 2012
Last Modified: August 7th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.