YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Link | Tags |
---|---|
https://github.com/ingydotnet/yaml-libyaml-pm/issues/120 | exploit issue tracking |
https://github.com/ingydotnet/yaml-libyaml-pm/pull/121 | patch issue tracking |
https://github.com/ingydotnet/yaml-libyaml-pm/pull/122 | patch issue tracking |