Lucene search

K
cve[email protected]CVE-2010-4512
HistoryDec 09, 2010 - 8:00 p.m.

CVE-2010-4512

2010-12-0920:00:18
CWE-264
web.nvd.nist.gov
20
cve-2010-4512
cobbler
umask value
local users
world writable permissions
nvd

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

Cobbler before 2.0.4 uses an incorrect umask value, which allows local users to have an unspecified impact by leveraging world writable permissions for files and directories.

Affected configurations

NVD
Node
michael_dehaancobblerRange2.0.3.1-2
OR
michael_dehaancobblerMatch0.1.1.7
OR
michael_dehaancobblerMatch0.2.1
OR
michael_dehaancobblerMatch0.2.2
OR
michael_dehaancobblerMatch0.2.3
OR
michael_dehaancobblerMatch0.2.5
OR
michael_dehaancobblerMatch0.2.7
OR
michael_dehaancobblerMatch0.2.8
OR
michael_dehaancobblerMatch0.2.9
OR
michael_dehaancobblerMatch0.3.0
OR
michael_dehaancobblerMatch0.3.1
OR
michael_dehaancobblerMatch0.3.3
OR
michael_dehaancobblerMatch0.3.4
OR
michael_dehaancobblerMatch0.3.5
OR
michael_dehaancobblerMatch0.3.6
OR
michael_dehaancobblerMatch0.3.7
OR
michael_dehaancobblerMatch0.3.9
OR
michael_dehaancobblerMatch0.4.0
OR
michael_dehaancobblerMatch0.4.2
OR
michael_dehaancobblerMatch0.4.3
OR
michael_dehaancobblerMatch0.4.5
OR
michael_dehaancobblerMatch0.4.6
OR
michael_dehaancobblerMatch0.4.7
OR
michael_dehaancobblerMatch0.4.8
OR
michael_dehaancobblerMatch0.5.0
OR
michael_dehaancobblerMatch0.6.0
OR
michael_dehaancobblerMatch0.6.1
OR
michael_dehaancobblerMatch0.6.3
OR
michael_dehaancobblerMatch0.6.4
OR
michael_dehaancobblerMatch0.6.5
OR
michael_dehaancobblerMatch0.8.1
OR
michael_dehaancobblerMatch0.8.3
OR
michael_dehaancobblerMatch1.0.0
OR
michael_dehaancobblerMatch1.0.2
OR
michael_dehaancobblerMatch1.0.2-1
OR
michael_dehaancobblerMatch1.0.3-1
OR
michael_dehaancobblerMatch1.2.0
OR
michael_dehaancobblerMatch1.2.2
OR
michael_dehaancobblerMatch1.2.3
OR
michael_dehaancobblerMatch1.2.5
OR
michael_dehaancobblerMatch1.2.6
OR
michael_dehaancobblerMatch1.2.7
OR
michael_dehaancobblerMatch1.2.8
OR
michael_dehaancobblerMatch1.2.8-1
OR
michael_dehaancobblerMatch1.2.9
OR
michael_dehaancobblerMatch1.2.9-1
OR
michael_dehaancobblerMatch1.3.1
OR
michael_dehaancobblerMatch1.3.1-1
OR
michael_dehaancobblerMatch1.3.3
OR
michael_dehaancobblerMatch1.3.3-1
OR
michael_dehaancobblerMatch1.3.4
OR
michael_dehaancobblerMatch1.3.4-1
OR
michael_dehaancobblerMatch1.4.0
OR
michael_dehaancobblerMatch1.4.0-2
OR
michael_dehaancobblerMatch1.4.1
OR
michael_dehaancobblerMatch1.4.1-1
OR
michael_dehaancobblerMatch1.4.2
OR
michael_dehaancobblerMatch1.4.2-1
OR
michael_dehaancobblerMatch1.4.3
OR
michael_dehaancobblerMatch1.4.3-4
OR
michael_dehaancobblerMatch1.6.1
OR
michael_dehaancobblerMatch1.6.1-1
OR
michael_dehaancobblerMatch1.6.2
OR
michael_dehaancobblerMatch1.6.2-1
OR
michael_dehaancobblerMatch1.6.3
OR
michael_dehaancobblerMatch1.6.3-1
OR
michael_dehaancobblerMatch1.6.4
OR
michael_dehaancobblerMatch1.6.4-1
OR
michael_dehaancobblerMatch1.6.5
OR
michael_dehaancobblerMatch1.6.5-1
OR
michael_dehaancobblerMatch1.6.6
OR
michael_dehaancobblerMatch1.6.6-1
OR
michael_dehaancobblerMatch1.6.8
OR
michael_dehaancobblerMatch1.6.8-1
OR
michael_dehaancobblerMatch2.0.0
OR
michael_dehaancobblerMatch2.0.0-1
OR
michael_dehaancobblerMatch2.0.1
OR
michael_dehaancobblerMatch2.0.1-1
OR
michael_dehaancobblerMatch2.0.3
OR
michael_dehaancobblerMatch2.0.3.1

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2010-4512