CVE

Id
17384  
CVE No.
CVE-2006-1280  
Status
Candidate  
Description
CGI::Session 4.03-1 does not set proper permissions on temporary files created in (1) Driver::File and (2) Driver::db_file, which allows local users to obtain privileged information, such as session keys, by viewing the files.  
Phase
Assigned (20060318)  
Votes
None (candidate not yet proposed)  
Comments