Lucene search

K
nvd[email protected]NVD:CVE-2012-2291
HistoryJan 21, 2013 - 9:55 p.m.

CVE-2012-2291

2013-01-2121:55:00
CWE-264
web.nvd.nist.gov
1

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.7

Confidence

High

EPSS

0

Percentile

5.1%

EMC Avamar Client 4.x, 5.x, and 6.x on HP-UX and Mac OS X, and the EMC Avamar plugin 4.x, 5.x, and 6.x for Oracle, uses world-writable permissions for cache directories, which allows local users to gain privileges via an unspecified symlink attack.

Affected configurations

Nvd
Node
emcavamarMatch4.0
OR
emcavamarMatch4.1
OR
emcavamarMatch5.0
OR
emcavamarMatch5.0sp1
OR
emcavamarMatch5.0sp2
OR
emcavamarMatch5.0.0-407
OR
emcavamarMatch5.0.4-26
OR
emcavamarMatch6.0
AND
applemac_os_x
OR
hphp-ux
Node
emcavamar_pluginMatch4.0-
OR
emcavamar_pluginMatch5.0-
OR
emcavamar_pluginMatch6.0-
OR
emcavamar_pluginMatch6.1-
VendorProductVersionCPE
emcavamar4.0cpe:2.3:a:emc:avamar:4.0:*:*:*:*:*:*:*
emcavamar4.1cpe:2.3:a:emc:avamar:4.1:*:*:*:*:*:*:*
emcavamar5.0cpe:2.3:a:emc:avamar:5.0:*:*:*:*:*:*:*
emcavamar5.0cpe:2.3:a:emc:avamar:5.0:sp1:*:*:*:*:*:*
emcavamar5.0cpe:2.3:a:emc:avamar:5.0:sp2:*:*:*:*:*:*
emcavamar5.0.0-407cpe:2.3:a:emc:avamar:5.0.0-407:*:*:*:*:*:*:*
emcavamar5.0.4-26cpe:2.3:a:emc:avamar:5.0.4-26:*:*:*:*:*:*:*
emcavamar6.0cpe:2.3:a:emc:avamar:6.0:*:*:*:*:*:*:*
applemac_os_x*cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
hphp-ux*cpe:2.3:o:hp:hp-ux:*:*:*:*:*:*:*:*
Rows per page:
1-10 of 141

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.7

Confidence

High

EPSS

0

Percentile

5.1%

Related for NVD:CVE-2012-2291