CVE-2012-3537
The Crowbar Ohai plugin (chef/cookbooks/ohai/files/default/plugins/crowbar.rb) in the Deployer Barclamp in Crowbar, possibly 1.4 and earlier, allows local users to execute arbitrary shell commands via vectors related to "insecure handling of tmp files"…
Does this matter?
Lower severity and a low EPSS score (0.59%). Track it; it rarely justifies an emergency change on its own.
Description
The Crowbar Ohai plugin (chef/cookbooks/ohai/files/default/plugins/crowbar.rb) in the Deployer Barclamp in Crowbar, possibly 1.4 and earlier, allows local users to execute arbitrary shell commands via vectors related to "insecure handling of tmp files" and predictable file names.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.59% probability · 46th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- dell/crowbar
- Source
- secalert@redhat.com
References
- http://osvdb.org/84955
- http://secunia.com/advisories/50442Vendor Advisory
- http://www.openwall.com/lists/oss-security/2012/08/27/5
- http://www.openwall.com/lists/oss-security/2012/08/27/7
- http://www.securityfocus.com/bid/55240
- https://bugzilla.novell.com/show_bug.cgi?id=774967
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78041
- https://github.com/SUSE-Cloud/barclamp-deployer/commit/5ea8d4ddaa4cb1ce834d36889f0fe7ac0d617bc8Exploit, Patch
- https://github.com/SUSE-Cloud/barclamp-deployer/commit/b6454268a067fc77ff5de82057b5b53b3cc38b87Exploit, Patch
- https://github.com/dellcloudedge/barclamp-deployer/pull/57
- http://osvdb.org/84955
- http://secunia.com/advisories/50442Vendor Advisory
- http://www.openwall.com/lists/oss-security/2012/08/27/5
- http://www.openwall.com/lists/oss-security/2012/08/27/7
- http://www.securityfocus.com/bid/55240
- https://bugzilla.novell.com/show_bug.cgi?id=774967
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78041
- https://github.com/SUSE-Cloud/barclamp-deployer/commit/5ea8d4ddaa4cb1ce834d36889f0fe7ac0d617bc8Exploit, Patch
- https://github.com/SUSE-Cloud/barclamp-deployer/commit/b6454268a067fc77ff5de82057b5b53b3cc38b87Exploit, Patch
- https://github.com/dellcloudedge/barclamp-deployer/pull/57
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.