CVE-2012-5635
The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2)…
Does this matter?
Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.
Description
The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and possibly other vectors, different vulnerabilities than CVE-2012-4417.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 0.32% probability · 24th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- gluster/glusterfs · redhat/storage management console · redhat/storage native client · redhat/storage server
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2013-0691.htmlVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=886364Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0691.htmlVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=886364Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.