CVE-2012-5635
GlusterFS: insecure temporary file creation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and possibly other vectors, different vulnerabilities than CVE-2012-4417.
La funcionalidad GlusterFS en Red Hat Storage Management Console v2.0, Native Client, Server 2.0 permite a usuarios locales sobreescribir archivos arbitrarios mediante un ataque de enlaces simbólicos en varios archivos temporales creados por (1) tests/volume.rc, (2) extras/hook- scripts/S30samba-stop.sh, y posiblemente otros vectores, la vulnerabilidad diferente a CVE-2012-4417.
Multiple insecure temporary file creation flaws were found in Red Hat Storage. A local user on the Red Hat Storage server could use these flaws to cause arbitrary files to be overwritten as the root user via a symbolic link attack.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-10-24 CVE Reserved
- 2013-03-29 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
- CWE-377: Insecure Temporary File
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2013-0691.html | 2023-02-13 | |
https://bugzilla.redhat.com/show_bug.cgi?id=886364 | 2013-03-28 | |
https://access.redhat.com/security/cve/CVE-2012-5635 | 2013-03-28 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gluster Search vendor "Gluster" | Glusterfs Search vendor "Gluster" for product "Glusterfs" | - | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Storage Management Console Search vendor "Redhat" for product "Storage Management Console" | 2.0 Search vendor "Redhat" for product "Storage Management Console" and version "2.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Storage Native Client Search vendor "Redhat" for product "Storage Native Client" | - | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Storage Server Search vendor "Redhat" for product "Storage Server" | 2.0 Search vendor "Redhat" for product "Storage Server" and version "2.0" | - |
Affected
|