Candidate: CVE-2014-1875 PublicDate: 2014-10-06 23:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1875 Description: The Capture::Tiny module before 0.24 for Perl allows local users to write to arbitrary files via a symlink attack on a temporary file. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737835 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_libcapture-tiny-perl: upstream_libcapture-tiny-perl: released (0.24-1) lucid_libcapture-tiny-perl: ignored (reached end-of-life) precise_libcapture-tiny-perl: ignored (reached end-of-life) precise/esm_libcapture-tiny-perl: DNE (precise was needed) quantal_libcapture-tiny-perl: ignored (reached end-of-life) saucy_libcapture-tiny-perl: ignored (reached end-of-life) trusty_libcapture-tiny-perl: not-affected (0.24-1) trusty/esm_libcapture-tiny-perl: DNE (trusty was not-affected [0.24-1]) utopic_libcapture-tiny-perl: not-affected (0.24-1) vivid_libcapture-tiny-perl: not-affected (0.24-1) vivid/stable-phone-overlay_libcapture-tiny-perl: DNE vivid/ubuntu-core_libcapture-tiny-perl: DNE wily_libcapture-tiny-perl: not-affected (0.24-1) xenial_libcapture-tiny-perl: not-affected (0.24-1) yakkety_libcapture-tiny-perl: not-affected (0.24-1) zesty_libcapture-tiny-perl: not-affected (0.24-1) devel_libcapture-tiny-perl: not-affected (0.24-1)