Lucene search

K
cve[email protected]CVE-2012-2291
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2012-2291

2022-10-0316:15:37
CWE-264
web.nvd.nist.gov
17
cve-2012-2291
emc avamar
client
plugin
vulnerability
hp-ux
mac os x
symlink attack

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.9 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

EMC Avamar Client 4.x, 5.x, and 6.x on HP-UX and Mac OS X, and the EMC Avamar plugin 4.x, 5.x, and 6.x for Oracle, uses world-writable permissions for cache directories, which allows local users to gain privileges via an unspecified symlink attack.

Affected configurations

NVD
Node
emcavamarMatch4.0
OR
emcavamarMatch4.1
OR
emcavamarMatch5.0
OR
emcavamarMatch5.0sp1
OR
emcavamarMatch5.0sp2
OR
emcavamarMatch5.0.0-407
OR
emcavamarMatch5.0.4-26
OR
emcavamarMatch6.0
AND
applemac_os_x
OR
hphp-ux
Node
emcavamar_pluginMatch4.0-
OR
emcavamar_pluginMatch5.0-
OR
emcavamar_pluginMatch6.0-
OR
emcavamar_pluginMatch6.1-

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.9 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2012-2291