CVE-2011-411631.01.2020, 18:15_is_safe in the File::Temp module for Perl does not properly handle symlinks.Link FollowingEnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTNIST3.3 LOWLOCALLOWLOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NredhatCNA------CVEADP------Base ScoreCVSS 3.xEPSS ScorePercentile: 42%Debian ReleasesDebian ProductCodenameperlbullseyeunimportantbullseye (security)unimportantbookwormunimportantsidunimportanttrixieunimportantUbuntu ReleasesUbuntu ProductCodenamelibfile-temp-perlquantaldneprecisedneoneiricignorednattyignoredmaverickignoredlucidignoredhardyignoredperlquantalignoredpreciseignoredoneiricignorednattyignoredmaverickignoredlucidignoredhardyignoredKnown Exploits!https://github.com/Perl-Toolchain-Gang/File-Temp/issues/14https://github.com/Perl-Toolchain-Gang/File-Temp/issues/14Common Weakness EnumerationCWE-59 - Improper Link Resolution Before File Access ('Link Following')The software attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.Referenceshttp://www.openwall.com/lists/oss-security/2011/11/04/2http://www.openwall.com/lists/oss-security/2011/11/04/4https://github.com/Perl-Toolchain-Gang/File-Temp/issues/14https://rt.cpan.org/Public/Bug/Display.html?id=69106https://seclists.org/oss-sec/2011/q4/238http://www.openwall.com/lists/oss-security/2011/11/04/2http://www.openwall.com/lists/oss-security/2011/11/04/4https://github.com/Perl-Toolchain-Gang/File-Temp/issues/14https://rt.cpan.org/Public/Bug/Display.html?id=69106https://seclists.org/oss-sec/2011/q4/238