HomeDefault status
unaffected
Any version before 0.903.0
affected
Description
YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified
Problem types
CWE-552 Files or Directories Accessible to External Parties
Product status
Any version before 0.903.0
Credits
@shlomif (Shlomi Fish)
References
github.com/ingydotnet/yaml-libyaml-pm/issues/120
github.com/ingydotnet/yaml-libyaml-pm/pull/121
github.com/ingydotnet/yaml-libyaml-pm/pull/122