CVE-2012-0052
published 2014-02-14CVE-2012-0052: Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 does not check the JON agent key, which allows remote attackers to spoof the…
PriorityP431medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
1.18%
64.2th percentile
Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 does not check the JON agent key, which allows remote attackers to spoof the identity of arbitrary agents via the registered agent name.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_operations_network | <= 2.4.1 | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
JON: Unapproved agents can connect using the name of an existing approved agent
vendor_redhat·2012-02-01·CVSS 5.8
CVE-2012-0052 [MEDIUM] JON: Unapproved agents can connect using the name of an existing approved agent
JON: Unapproved agents can connect using the name of an existing approved agent
Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 does not check the JON agent key, which allows remote attackers to spoof the identity of arbitrary agents via the registered agent name.
Red Hat
kernel: proc: /proc/<pid>/mem mem_write insufficient permission checking
vendor_redhat·2012-01-18·CVSS 6.9
CVE-2012-0056 [MEDIUM] CWE-863 kernel: proc: /proc/<pid>/mem mem_write insufficient permission checking
kernel: proc: /proc//mem mem_write insufficient permission checking
The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when writing to /proc//mem, which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper.
Statement: This issue did not affect the version of Linux kernel as shipped with Red Hat Enterprise Linux 4 and 5 as it did not backport the upstream commit 198214a7ee. This has been addressed in Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2012-0052.html and https://rhn.redhat.com/errata/RHSA-2012-0061.html. For more information, please read https://access.redhat.com/kb/docs/DOC-69129.
Package: kernel (Red Hat Enterprise Linux
GHSA
GHSA-fhpq-g3rr-xhmq: Red Hat JBoss Operations Network (JON) before 2
ghsa_unreviewed·2022-05-04
CVE-2012-0052 [MEDIUM] CWE-20 GHSA-fhpq-g3rr-xhmq: Red Hat JBoss Operations Network (JON) before 2
Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 does not check the JON agent key, which allows remote attackers to spoof the identity of arbitrary agents via the registered agent name.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-4401 moodle: Course topics permission issue (MSA-12-0052)
bugzilla·2012-09-17·CVSS 4.0
CVE-2012-4401 [MEDIUM] CVE-2012-4401 moodle: Course topics permission issue (MSA-12-0052)
CVE-2012-4401 moodle: Course topics permission issue (MSA-12-0052)
A security flaw was found in the way Moodle course management system performed user permissions validation by course topic management. A remote attackers, with course editing capabilities, but without ability to show / hide topics or set the current topic for a particular course could use this flaw to successfully complete these actions under certain circumstances.
Upstream patch:
[1] http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-28207
References:
[2] http://www.openwall.com/lists/oss-security/2012/09/17/1
Discussion:
This issue affects the version of the moodle package, as shipped with Fedora release of 17 (the upstream course/view.php patch part is applicable).
--
This issue did NOT affect t
Bugzilla
CVE-2012-2922 drupal7: full path disclosure vulnerability
bugzilla·2012-05-23·CVSS 5.0
CVE-2012-2922 [MEDIUM] CVE-2012-2922 drupal7: full path disclosure vulnerability
CVE-2012-2922 drupal7: full path disclosure vulnerability
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-2922 to
the following vulnerability:
Name: CVE-2012-2922
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2922
Assigned: 20120521
Reference: BUGTRAQ:20120510 Drupal 7.14 <= Full Path Disclosure Vulnerability
Reference: http://archives.neohapsis.com/archives/bugtraq/2012-05/0052.html
Reference: BUGTRAQ:20120510 Drupal 7.14 <= Full Path Disclosure Vulnerability (Update)
Reference: http://archives.neohapsis.com/archives/bugtraq/2012-05/0053.html
Reference: BUGTRAQ:20120510 Re: Drupal 7.14 <= Full Path Disclosure Vulnerability
Reference: http://archives.neohapsis.com/archives/bugtraq/2012-05/0055.html
Reference: http://www.securityfocus.com/bid/53454
Refer
Bugzilla
CVE-2012-0052 JON: Unapproved agents can connect using the name of an existing approved agent
bugzilla·2012-01-16·CVSS 5.8
CVE-2012-0052 [MEDIUM] CVE-2012-0052 JON: Unapproved agents can connect using the name of an existing approved agent
CVE-2012-0052 JON: Unapproved agents can connect using the name of an existing approved agent
If a JON agent is registered in a JON server's inventory with a given name, then any other agent can connect to the JON server and assume the identity of this registered agent simply by assuming its agent name. The JON agent key is not verified, allowing malicious JON agents to connect to the server.
Discussion:
This issue has been addressed in following products:
JBoss Operations Network 2.4.2
Via RHSA-2012:0089 https://rhn.redhat.com/errata/RHSA-2012-0089.html
---
This issue has been addressed in following products:
JBoss Operations Network 3.0.1
Via RHSA-2012:0406 https://rhn.redhat.com/errata/RHSA-2012-0406.html
2014-02-14
Published