{"id":"CVE-2016-10374","details":"perltidy through 20160302, as used by perlcritic, check-all-the-things, and other software, relies on the current working directory for certain output files and does not have a symlink-attack protection mechanism, which allows local users to overwrite arbitrary files by creating a symlink, as demonstrated by creating a perltidy.ERR symlink that the victim cannot delete.","modified":"2026-04-16T06:22:26.180607776Z","published":"2017-05-17T19:29:00.117Z","references":[{"type":"REPORT","url":"https://bugs.debian.org/862667"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-10374.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"2016-03-02"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"}]}