Security Advisories (2)
CVE-2011-4114 (2011-07-18)

PAR packed files are extracted to unsafe and predictable temporary directories (this bug was originally reported against PAR::Packer, but it applies to PAR as well).

CVE-2011-5060 (2012-01-13)

The par_mktmpdir function in the PAR module before 1.003 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program, a different vulnerability in a different package than CVE-2011-4114.

Documentation

Frequently Asked Questions about PAR
Cross-Platform Packaging and Deployment with PAR
Make and run Perl Archives
Binary PAR Loader
pp
Perl Packager
frontend to pp written in Perl/Tk

Modules

Pack applications in a single executable file
PAR
Perl Archive Toolkit
Input filter for PAR
Bleach filter
Bytecode filter
Obfuscating filter
Content patcher
POD-stripping filter
PAR guts
App::Packer backend for making PAR files