// For flags

CVE-2012-3329

 

Severity Score

3.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

IBM Advanced Settings Utility (ASU) through 3.62 and 3.70 through 9.21 and Bootable Media Creator (BoMC) through 2.30 and 3.00 through 9.21 on Linux allow local users to overwrite arbitrary files via a symlink attack on a (1) temporary file or (2) log file.

IBM Advanced Settings Utility (ASU) hasta la v3.62 y v3.70 hasta la v9.21 y Bootable Media Creator (BOMC) hasta la v2.30 y v3.00 hasta la v9.21 en Linux permiten a los usuarios locales sobreescribir ficheros de su elección mediante un ataque de enlaces simbólicos en un archivo (1) temporal o (2) el archivo de registro.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-06-07 CVE Reserved
  • 2012-12-19 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-59: Improper Link Resolution Before File Access ('Link Following')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ibm
Search vendor "Ibm"
Advanced Settings Utility
Search vendor "Ibm" for product "Advanced Settings Utility"
3.62
Search vendor "Ibm" for product "Advanced Settings Utility" and version "3.62"
-
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
*-
Safe
Ibm
Search vendor "Ibm"
Advanced Settings Utility
Search vendor "Ibm" for product "Advanced Settings Utility"
3.70
Search vendor "Ibm" for product "Advanced Settings Utility" and version "3.70"
-
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
*-
Safe
Ibm
Search vendor "Ibm"
Advanced Settings Utility
Search vendor "Ibm" for product "Advanced Settings Utility"
9.21
Search vendor "Ibm" for product "Advanced Settings Utility" and version "9.21"
-
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
*-
Safe
Ibm
Search vendor "Ibm"
Bootable Media Creator
Search vendor "Ibm" for product "Bootable Media Creator"
2.30
Search vendor "Ibm" for product "Bootable Media Creator" and version "2.30"
-
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
*-
Safe
Ibm
Search vendor "Ibm"
Bootable Media Creator
Search vendor "Ibm" for product "Bootable Media Creator"
3.00
Search vendor "Ibm" for product "Bootable Media Creator" and version "3.00"
-
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
*-
Safe
Ibm
Search vendor "Ibm"
Bootable Media Creator
Search vendor "Ibm" for product "Bootable Media Creator"
9.21
Search vendor "Ibm" for product "Bootable Media Creator" and version "9.21"
-
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
*-
Safe