Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-0787
HistoryNov 23, 2013 - 12:00 a.m.

CVE-2012-0787

2013-11-2300:00:00
ubuntu.com
ubuntu.com
12

3.7 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:H/Au:N/C:P/I:P/A:P

0.0004 Low

EPSS

Percentile

5.1%

The clone_file function in transfer.c in Augeas before 1.0.0, when
copy_if_rename_fails is set and EXDEV or EBUSY is returned by the rename
function, allows local users to overwrite arbitrary files and obtain
sensitive information via a bind mount on the (1) .augsave or (2)
destination file when using the backup save option, or (3) .augnew file
when using the newfile save option.

Bugs

3.7 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:H/Au:N/C:P/I:P/A:P

0.0004 Low

EPSS

Percentile

5.1%