Candidate: CVE-2008-5303 PublicDate: 2008-12-01 17:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5303 https://ubuntu.com/security/notices/USN-700-1 Description: Race condition in the rmtree function in File::Path 1.08 (lib/File/Path.pm) in Perl 5.8.8 allows local users to to delete arbitrary files via a symlink attack, a different vulnerability than CVE-2005-0448, CVE-2004-0452, and CVE-2008-2827. NOTE: this is a regression error related to CVE-2005-0448. It is different from CVE-2008-5302 due to affected versions. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: kees CVSS: Patches_perl: upstream_perl: needs-triage dapper_perl: not-affected (5.8.7-10ubuntu1.1) gutsy_perl: released (5.8.8-7ubuntu3.4) hardy_perl: released (5.8.8-12ubuntu0.3) intrepid_perl: not-affected devel_perl: not-affected