CVE-2012-0051
published 2019-11-07CVE-2012-0051: Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon retrieval.
PriorityP345high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
1.71%
75.1th percentile
Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon retrieval.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | tahoe-lafs | — | — |
| tahoe-lafs | tahoe-lafs | — | — |
| tahoe-lafs | tahoe-lafs | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_debian7.4LOW
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Tahoe-LAFS fails to ensure integrity
ghsa·2022-04-23
CVE-2012-0051 [MEDIUM] Tahoe-LAFS fails to ensure integrity
Tahoe-LAFS fails to ensure integrity
Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon retrieval.
OSV
Tahoe-LAFS fails to ensure integrity
osv·2022-04-23
CVE-2012-0051 [MEDIUM] Tahoe-LAFS fails to ensure integrity
Tahoe-LAFS fails to ensure integrity
Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon retrieval.
Debian
CVE-2012-0051: tahoe-lafs - Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corr...
vendor_debian·2012·CVSS 7.4
CVE-2012-0051 [HIGH] CVE-2012-0051: tahoe-lafs - Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corr...
Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon retrieval.
Scope: local
sid: resolved
trixie: resolved
Red Hat
kernel: kvm: pit timer with no irqchip crashes the system
vendor_redhat·2011-12-14·CVSS 4.9
CVE-2011-4622 [MEDIUM] kernel: kvm: pit timer with no irqchip crashes the system
kernel: kvm: pit timer with no irqchip crashes the system
The create_pit_timer function in arch/x86/kvm/i8254.c in KVM 83, and possibly other versions, does not properly handle when Programmable Interval Timer (PIT) interrupt requests (IRQs) when a virtual interrupt controller (irqchip) is not available, which allows local users to cause a denial of service (NULL pointer dereference) by starting a timer.
Statement: This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4 and Red Hat Enterprise MRG as they did not provide support for the KVM subsystem. It has been addressed in Red Hat Enterprise 5 and 6 via https://rhn.redhat.com/errata/RHSA-2012-0051.html and https://rhn.redhat.com/errata/RHSA-2012-0350.html.
Package: kernel (Red Hat Enterprise L
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2012/01/15/11http://www.openwall.com/lists/oss-security/2012/01/26/7http://www.openwall.com/lists/oss-security/2012/01/26/8http://www.openwall.com/lists/oss-security/2012/01/26/9https://security-tracker.debian.org/tracker/CVE-2012-0051https://tahoe-lafs.org/trac/tahoe-lafs/ticket/1654http://www.openwall.com/lists/oss-security/2012/01/15/11http://www.openwall.com/lists/oss-security/2012/01/26/7http://www.openwall.com/lists/oss-security/2012/01/26/8http://www.openwall.com/lists/oss-security/2012/01/26/9https://security-tracker.debian.org/tracker/CVE-2012-0051https://tahoe-lafs.org/trac/tahoe-lafs/ticket/1654
2019-11-07
Published