CyberRota Analysis
AI-GeneratedThe vulnerability affects Data::NDArray::Shared versions prior to 0.02 for Perl, allowing local users to exploit a world-readable memory-mapped file created without proper access controls. This can lead to unauthorized access to sensitive IPC payloads and potential manipulation of files through symlink attacks. Organizations using this Perl module should prioritize remediation to mitigate the risk of local privilege escalation and data exposure.
Original NVD Description
Data::NDArray::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in ndarray.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW is absent, so a symlink planted at the path is followed, and O_EXCL is absent, so the open silently uses a pre-planted file instead of failing. A "Shared" segment naturally lives in a shared directory such as /tmp or /dev/shm, where any local user can read the IPC payloads stored in the world-readable segment, and a pre-planted file or symlink at the path lets a local attacker win a pre-creation race or redirect the open.