CVE-2012-0786Link Following in Augeas

Severity
3.3LOWNVD
EPSS
0.1%
top 84.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 23
Latest updateMay 17

Description

The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on a .augnew file.

CVSS vector

AV:L/AC:M/C:P/I:P/A:NExploitability: 3.4 | Impact: 4.9

Affected Packages3 packages

debiandebian/augeas< augeas 1.0.0-1 (bookworm)
Debianaugeas/augeas< 1.0.0-1+3
NVDaugeas/augeas0.10.0+36

🔴Vulnerability Details

4
GHSA
GHSA-2x6r-rq7f-fcrj: The transform_save function in transform2022-05-17
GHSA
GHSA-v2f6-mg42-536m: The transform_save function in transform2022-05-17
OSV
CVE-2012-6607: The transform_save function in transform2013-11-23
OSV
CVE-2012-0786: The transform_save function in transform2013-11-23

📋Vendor Advisories

4
Red Hat
augeas: symlink attack on a .augsave file2013-11-21
Red Hat
augeas: susceptible to symlink attack2012-08-11
Debian
CVE-2012-0786: augeas - The transform_save function in transform.c in Augeas before 1.0.0 allows local u...2012
Debian
CVE-2012-6607: augeas - The transform_save function in transform.c in Augeas before 1.0.0 allows local u...2012

💬Community

6
Bugzilla
CVE-2013-6412 augeas: incorrect permissions set on newly created files2013-11-25
Bugzilla
CVE-2012-6607 augeas: symlink attack on a .augsave file2013-11-25
Bugzilla
CVE-2012-0787 CVE-2012-0786 augeas: various flaws [epel-4]2013-11-22
Bugzilla
CVE-2012-0787 CVE-2012-0786 augeas: various flaws [epel-5]2013-11-22
Bugzilla
CVE-2012-0787 CVE-2012-0786 augeas: various flaws [fedora-all]2013-11-22