{"id":"ECHO-d134-92e0-c60b","summary":"It's pretty dodgy to consider this not applicable, because the CVE can easily be exploited.\nThe vulnerability is in the function is_safe(), which when given a path with symlinks can claim a path\ncannot be accessed by another user falsely.\nThe justification mostly boils down to the function not being supposed to be relied on for security, but\nfor safety. In other words it's to make sure the user doesn't do stupid things, not to protect against\nattackers. There is extra nuance in that the function claims to do some things and not be exhaustive anyway,\nbut it's documentation does not mention it cannot follow symlinks.\nThere is no fix upstream or any intention of fixing it, and the fix would almost certainly be a documentation change.\nJustification: https://seclists.org/oss-sec/2011/q4/234\nBug report and exploit: https://rt.cpan.org/Public/Bug/Display.html?id=69106\nVulnerable code: https://github.com/Perl/perl5/blob/blead/cpan/File-Temp/lib/File/Temp.pm\nCVE: https://security-tracker.debian.org/tracker/CVE-2011-4116\n","modified":"2026-09-15T03:42:50.758699154Z","published":"2025-09-15T01:08:40.029347Z","withdrawn":"2025-08-03T16:59:07.579Z","upstream":["CVE-2011-4116","GHSA-grqm-6jmc-2h46"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2011-4116"}],"affected":[{"package":{"name":"perl","ecosystem":"Echo","purl":"pkg:deb/echo/perl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.36.0-7+deb12u1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-d134-92e0-c60b.json"}}],"schema_version":"1.9.0"}