CVE-2012-0787
published 2013-11-23CVE-2012-0787: The clone_file function in transfer.c in Augeas before 1.0.0, when copy_if_rename_fails is set and EXDEV or EBUSY is returned by the rename function, allows…
PriorityP412low3.7CVSS 2.0
AVLACHAuNCPIPAP
EPSS
0.41%
33.5th percentile
The clone_file function in transfer.c in Augeas before 1.0.0, when copy_if_rename_fails is set and EXDEV or EBUSY is returned by the rename function, allows local users to overwrite arbitrary files and obtain sensitive information via a bind mount on the (1) .augsave or (2) destination file when using the backup save option, or (3) .augnew file when using the newfile save option.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| augeas | augeas | <= 0.10.0 | — |
| augeas | augeas | — | — |
| augeas | augeas | — | — |
| augeas | augeas | — | — |
| augeas | augeas | — | — |
| augeas | augeas | — | — |
| augeas | augeas | — | — |
| augeas | augeas | — | — |
| augeas | augeas | — | — |
| augeas | augeas | — | — |
| augeas | augeas | — | — |
| augeas | augeas | — | — |
| augeas | augeas | — | — |
| augeas | augeas | — | — |
| augeas | augeas | — | — |
| augeas | augeas | — | — |
| augeas | augeas | — | — |
| augeas | augeas | — | — |
| augeas | augeas | — | — |
| augeas | augeas | — | — |
| augeas | augeas | — | — |
| augeas | augeas | — | — |
| augeas | augeas | — | — |
| augeas | augeas | — | — |
| augeas | augeas | — | — |
CVSS provenance
nvdv2.03.7LOWAV:L/AC:H/Au:N/C:P/I:P/A:P
osv3.7LOW
vendor_debian3.7LOW
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8qr9-h3xv-vhx6: The clone_file function in transfer
ghsa_unreviewed·2022-05-14
CVE-2012-0787 [LOW] GHSA-8qr9-h3xv-vhx6: The clone_file function in transfer
The clone_file function in transfer.c in Augeas before 1.0.0, when copy_if_rename_fails is set and EXDEV or EBUSY is returned by the rename function, allows local users to overwrite arbitrary files and obtain sensitive information via a bind mount on the (1) .augsave or (2) destination file when using the backup save option, or (3) .augnew file when using the newfile save option.
OSV
CVE-2012-0787: The clone_file function in transfer
osv·2013-11-23·CVSS 3.7
CVE-2012-0787 [LOW] CVE-2012-0787: The clone_file function in transfer
The clone_file function in transfer.c in Augeas before 1.0.0, when copy_if_rename_fails is set and EXDEV or EBUSY is returned by the rename function, allows local users to overwrite arbitrary files and obtain sensitive information via a bind mount on the (1) .augsave or (2) destination file when using the backup save option, or (3) .augnew file when using the newfile save option.
Red Hat
augeas: susceptible to mountpoint attack
vendor_redhat·2012-07-19·CVSS 3.7
CVE-2012-0787 [LOW] augeas: susceptible to mountpoint attack
augeas: susceptible to mountpoint attack
The clone_file function in transfer.c in Augeas before 1.0.0, when copy_if_rename_fails is set and EXDEV or EBUSY is returned by the rename function, allows local users to overwrite arbitrary files and obtain sensitive information via a bind mount on the (1) .augsave or (2) destination file when using the backup save option, or (3) .augnew file when using the newfile save option.
Package: augeas (Red Hat OpenStack Platform 3) - Affected
Debian
CVE-2012-0787: augeas - The clone_file function in transfer.c in Augeas before 1.0.0, when copy_if_renam...
vendor_debian·2012·CVSS 3.7
CVE-2012-0787 [LOW] CVE-2012-0787: augeas - The clone_file function in transfer.c in Augeas before 1.0.0, when copy_if_renam...
The clone_file function in transfer.c in Augeas before 1.0.0, when copy_if_rename_fails is set and EXDEV or EBUSY is returned by the rename function, allows local users to overwrite arbitrary files and obtain sensitive information via a bind mount on the (1) .augsave or (2) destination file when using the backup save option, or (3) .augnew file when using the newfile save option.
Scope: local
bookworm: resolved (fixed in 1.0.0-1)
bullseye: resolved (fixed in 1.0.0-1)
forky: resolved (fixed in 1.0.0-1)
sid: resolved (fixed in 1.0.0-1)
trixie: resolved (fixed in 1.0.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-6607 augeas: symlink attack on a .augsave file
bugzilla·2013-11-25·CVSS 3.3
CVE-2012-6607 [LOW] CVE-2012-6607 augeas: symlink attack on a .augsave file
CVE-2012-6607 augeas: symlink attack on a .augsave file
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-6607 to
the following vulnerability:
Name: CVE-2012-6607
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6607
Assigned: 20131123
Reference: http://augeas.net/news.html
Reference: https://bugzilla.redhat.com/show_bug.cgi?id=772257
Reference: https://github.com/hercules-team/augeas/commit/16387744
Reference: REDHAT:RHSA-2013:1537
Reference: http://rhn.redhat.com/errata/RHSA-2013-1537.html
Reference: SECUNIA:55811
Reference: http://secunia.com/advisories/55811
The transform_save function in transform_save in Augeas before 1.0.0 allows local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on a .augsave file in a bac
Bugzilla
CVE-2012-0787 CVE-2012-0786 augeas: various flaws [epel-4]
bugzilla·2013-11-22·CVSS 3.3
CVE-2012-0787 [LOW] CVE-2012-0787 CVE-2012-0786 augeas: various flaws [epel-4]
CVE-2012-0787 CVE-2012-0786 augeas: various flaws [epel-4]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-4 tracking bug for augeas: see block
Bugzilla
CVE-2012-0787 CVE-2012-0786 augeas: various flaws [epel-5]
bugzilla·2013-11-22·CVSS 3.3
CVE-2012-0787 [LOW] CVE-2012-0787 CVE-2012-0786 augeas: various flaws [epel-5]
CVE-2012-0787 CVE-2012-0786 augeas: various flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 tracking bug for augeas: see block
Bugzilla
CVE-2012-0787 CVE-2012-0786 augeas: various flaws [fedora-all]
bugzilla·2013-11-22·CVSS 3.3
CVE-2012-0787 [LOW] CVE-2012-0787 CVE-2012-0786 augeas: various flaws [fedora-all]
CVE-2012-0787 CVE-2012-0786 augeas: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multiple s
Bugzilla
CVE-2012-0787 augeas: susceptible to mountpoint attack
bugzilla·2012-01-06·CVSS 3.7
CVE-2012-0787 [LOW] CVE-2012-0787 augeas: susceptible to mountpoint attack
CVE-2012-0787 augeas: susceptible to mountpoint attack
Augeas is a configuration management API that represents the contents of config
files as a tree in memory for editing, with the edits being written back to the
actual file. By default it loads files it understands in a large number of
standard system locations (/etc, /boot), but can also open files in a user
specified location [1],[2].
It has two save modes of interest, "backup" that keeps the original in
PATH.augorig and "newfile" that leaves the file alone, but writes the edited
version to PATH.augnew. These can be set via the API [3] or --backup/--new with
augtool (CLI tool around the API).
A flaw was found in the current 0.10.0 version and most previous versions. It
requires that the directory containing the file to be edited is
http://augeas.net/news.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1537.htmlhttp://secunia.com/advisories/55811https://bugzilla.redhat.com/show_bug.cgi?id=772261https://github.com/hercules-team/augeas/commit/b8de6a8chttp://augeas.net/news.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1537.htmlhttp://secunia.com/advisories/55811https://bugzilla.redhat.com/show_bug.cgi?id=772261https://github.com/hercules-team/augeas/commit/b8de6a8c
2013-11-23
Published