Lucene search

K
cve[email protected]CVE-2012-5635
HistoryApr 09, 2013 - 8:55 p.m.

CVE-2012-5635

2013-04-0920:55:01
CWE-264
web.nvd.nist.gov
32
cve-2012-5635
glusterfs
red hat storage management console
symlink attack
file overwrite
nvd

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

6.5 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and possibly other vectors, different vulnerabilities than CVE-2012-4417.

Affected configurations

NVD
Node
glusterglusterfsMatch-
OR
redhatstorage_management_consoleMatch2.0
OR
redhatstorage_native_clientMatch-
OR
redhatstorage_serverMatch2.0

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

6.5 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%