Config-IniFiles 2.68 Deleted
Security Advisories
CVE-2012-2451
The Config::IniFiles module before 2.71 for Perl creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack. NOTE: some of these details are obtained from third party information. NOTE: it has been reported that this might only be exploitable by writing in the same directory as the .ini file. If this is the case, then this issue might not cross privilege boundaries.
- http://www.openwall.com/lists/oss-security/2012/05/02/6
- http://www.osvdb.org/81671
- http://secunia.com/advisories/48990
- https://bitbucket.org/shlomif/perl-config-inifiles/changeset/a08fa26f4f59
- https://bugzilla.redhat.com/show_bug.cgi?id=818386
- http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080713.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080716.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-May/081207.html
- http://www.securityfocus.com/bid/53361
- http://www.ubuntu.com/usn/USN-1543-1
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75328
Reported: 2012-06-27
Kwalitee Issues
- has_human_readable_license
-
Add a section called "LICENSE" to the documentation, or add a file named LICENSE to the distribution.
- has_license_in_source_file
-
Add =head1 LICENSE and the text of the license to the main module in your code.
- no_pod_errors
-
Remove the POD errors. You can check for POD errors automatically by including Test::Pod to your test suite.
Error: Config-IniFiles-2.68/lib/Config/IniFiles.pm -- Around line 249: alternative text '/ReadConfig' contains non-escaped | or / Around line 270: alternative text '/WriteConfig' contains non-escaped | or / Around line 2658: Non-ASCII character seen before =encoding in 'Röpke,'. Assuming CP1252
- meta_yml_declares_perl_version
-
If you are using Build.PL define the {requires}{perl} = VERSION field. If you are using MakeMaker (Makefile.PL) you should upgrade ExtUtils::MakeMaker to 6.48 and use MIN_PERL_VERSION parameter. Perl::MinimumVersion can help you determine which version of Perl your module needs.
- has_meta_json
-
Add a META.json to the distribution. Your buildtool should be able to autogenerate it.
- has_known_license_in_source_file
-
Add =head1 LICENSE and/or the proper text of the well-known license to the main module in your code.
- use_warnings
-
Add 'use warnings' (or its equivalents) to all modules, or convince us that your favorite module is well-known enough and people can easily see the modules warn when something bad happens.
Error: Config::IniFiles
- has_separate_license_file
-
This is not a critical issue. Currently mainly informative for the CPANTS authors. It might be removed later.
Modules
Name | Abstract | Version | View |
---|---|---|---|
Config::IniFiles | A module for reading .ini-style configuration files. | 2.68 | metacpan |