Security Advisories (1)
CVE-2017-6512 (2017-05-02)

Race condition in the rmtree and remove_tree functions allows attackers to set the mode on arbitrary files via vectors involving directory-permission loosening logic.

Changes for version 2.07_03 - 2009-06-21

  • Merged 2.07_02 patches from blead
  • Remove stat checks on Windows platform (inhibits UNC path removals from working, and Windows is immune to this particular attack). CPAN #34701

Modules

Create or remove directory trees