CVE-2012-0860
published 2013-01-04CVE-2012-0860: Multiple untrusted search path vulnerabilities in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, allow local users to gain…
PriorityP419medium6.2CVSS 2.0
AVLACHAuNCCICAC
EPSS
0.40%
32.1th percentile
Multiple untrusted search path vulnerabilities in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, allow local users to gain privileges via a Trojan horse (1) deployUtil.py or (2) vds_bootstrap.py Python module in /tmp/.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_virtualization_manager | <= 3.0 | — |
| redhat | enterprise_virtualization_manager | — | — |
| redhat | enterprise_virtualization_manager | — | — |
| redhat | enterprise_virtualization_manager | — | — |
CVSS provenance
nvdv2.06.2MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4mjh-cm44-g6gj: Multiple untrusted search path vulnerabilities in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3
ghsa_unreviewed·2022-05-17
CVE-2012-0860 [MEDIUM] GHSA-4mjh-cm44-g6gj: Multiple untrusted search path vulnerabilities in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3
Multiple untrusted search path vulnerabilities in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, allow local users to gain privileges via a Trojan horse (1) deployUtil.py or (2) vds_bootstrap.py Python module in /tmp/.
Red Hat
rhev: vds_installer insecure /tmp use
vendor_redhat·2012-12-04·CVSS 6.2
CVE-2012-0860 [MEDIUM] CWE-377 rhev: vds_installer insecure /tmp use
rhev: vds_installer insecure /tmp use
Multiple untrusted search path vulnerabilities in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, allow local users to gain privileges via a Trojan horse (1) deployUtil.py or (2) vds_bootstrap.py Python module in /tmp/.
Statement: This issue does affect Red Hat Enterprise Virtualization 2 and 3.
Red Hat Enterprise Virtualization 2 is now in Production 2 phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Virtualization Life Cycle: https://access.redhat.com/support/policy/updates/rhev/.
Package: ovirt-engine-backend (Red Hat Enterprise Virtualization 2) - Will not fix
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2012-1506.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1508.htmlhttp://www.securityfocus.com/bid/56825http://www.securitytracker.com/id?1027838https://bugzilla.redhat.com/show_bug.cgi?id=790730https://exchange.xforce.ibmcloud.com/vulnerabilities/80543http://rhn.redhat.com/errata/RHSA-2012-1506.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1508.htmlhttp://www.securityfocus.com/bid/56825http://www.securitytracker.com/id?1027838https://bugzilla.redhat.com/show_bug.cgi?id=790730https://exchange.xforce.ibmcloud.com/vulnerabilities/80543
2013-01-04
Published