Bug 832538 (CVE-2013-4184) - VUL-1: CVE-2013-4184: perl-Data-UUID: symlink attacks
Summary: VUL-1: CVE-2013-4184: perl-Data-UUID: symlink attacks
Status: RESOLVED WORKSFORME
Alias: CVE-2013-4184
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/90689/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2013-07-31 12:07 UTC by Matthias Weckbecker
Modified: 2017-08-17 14:39 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Matthias Weckbecker 2013-07-31 12:07:25 UTC
Via oss-sec [1]: 

=========================================================================
Hi all,

The Perl module Data::UUID from CPAN is vulnerable to symlink attacks.
 This is a widely used Perl module for generating UUIDs.

Details are in the bug report on github:
https://github.com/rjbs/Data-UUID/issues/5

I believe all released versions are affected - I have confirmed the
issue against 1.219.

Regarding affected distributions, note that Debian and Fedora do not
ship Data::UUID from CPAN - they use OSSP's uuid.  However, at least
Arch and Gentoo seem to ship the CPAN version.

I've not previously requested a CVE id for this, it's an open source
request, and it's not embargoed.

Kind regards,

-- 
Tim Retout <tim@retout.co.uk>
=========================================================================

[1] http://seclists.org/oss-sec/2013/q3/251
Comment 1 Matthias Weckbecker 2013-07-31 12:08:29 UTC
Note: sdk only
Comment 2 SMASH SMASH 2014-07-02 11:35:14 UTC
Affected packages:

SLE-11-SP3: perl-Data-UUID
Comment 4 Andreas Stieger 2017-08-17 13:14:46 UTC
dropped from openSUSE, SLE 11 only had the debuginfo,debugsource