cbcvebase.
CVE-2012-0787
published 2013-11-23

CVE-2012-0787: The clone_file function in transfer.c in Augeas before 1.0.0, when copy_if_rename_fails is set and EXDEV or EBUSY is returned by the rename function, allows…

PriorityP412low3.7CVSS 2.0
AVLACHAuNCPIPAP
EPSS
0.41%
33.5th percentile
The clone_file function in transfer.c in Augeas before 1.0.0, when copy_if_rename_fails is set and EXDEV or EBUSY is returned by the rename function, allows local users to overwrite arbitrary files and obtain sensitive information via a bind mount on the (1) .augsave or (2) destination file when using the backup save option, or (3) .augnew file when using the newfile save option.

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
augeasaugeas<= 0.10.0
augeasaugeas
augeasaugeas
augeasaugeas
augeasaugeas
augeasaugeas
augeasaugeas
augeasaugeas
augeasaugeas
augeasaugeas
augeasaugeas
augeasaugeas
augeasaugeas
augeasaugeas
augeasaugeas
augeasaugeas
augeasaugeas
augeasaugeas
augeasaugeas
augeasaugeas
augeasaugeas
augeasaugeas
augeasaugeas
augeasaugeas
augeasaugeas

CVSS provenance

nvdv2.03.7LOWAV:L/AC:H/Au:N/C:P/I:P/A:P
osv3.7LOW
vendor_debian3.7LOW
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.