Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-5638
HistoryDec 20, 2012 - 12:00 a.m.

CVE-2012-5638

2012-12-2000:00:00
ubuntu.com
ubuntu.com
11

CVSS2

3.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:P/A:P

EPSS

0

Percentile

5.1%

The setup_logging function in log.h in SANLock uses world-writable
permissions for /var/log/sanlock.log, which allows local users to overwrite
the file content or bypass intended disk-quota restrictions via standard
filesystem write operations.

CVSS2

3.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:P/A:P

EPSS

0

Percentile

5.1%