VulnerabilityModified
CVE-2012-1586
mount.cifs in cifs-utils 2.6 allows local users to determine the existence of arbitrary files or directories via the file path in the second argument, which reveals their existence in an error message.
LOW 2.1EPSS 0.73%
Does this matter?
Lower severity and a low EPSS score (0.73%). Track it; it rarely justifies an emergency change on its own.
Description
mount.cifs in cifs-utils 2.6 allows local users to determine the existence of arbitrary files or directories via the file path in the second argument, which reveals their existence in an error message.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.73% probability · 52th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- debian/cifs-utils
- Source
- secalert@redhat.com
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=665923
- http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00024.html
- http://www.openwall.com/lists/oss-security/2012/03/27/1
- http://www.openwall.com/lists/oss-security/2012/03/27/6
- https://bugzilla.samba.org/show_bug.cgi?id=8821
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=665923
- http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00024.html
- http://www.openwall.com/lists/oss-security/2012/03/27/1
- http://www.openwall.com/lists/oss-security/2012/03/27/6
- https://bugzilla.samba.org/show_bug.cgi?id=8821
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.