CVE-2012-3449
published 2012-08-07CVE-2012-3449: Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/pki/controllerca/incoming/ and (2) /var/lib/openvswitch/pki/switchca/incoming/…
PriorityP411low3.6CVSS 2.0
AVLACLAuNCNIPAP
EPSS
0.35%
27.1th percentile
Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/pki/controllerca/incoming/ and (2) /var/lib/openvswitch/pki/switchca/incoming/, which allows local users to delete and overwrite arbitrary files.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openvswitch | < openvswitch 1.4.2+git20120612-8 (bookworm) | openvswitch 1.4.2+git20120612-8 (bookworm) |
| openvswitch | openvswitch | — | — |
| openvswitch | openvswitch | >= 0 < 1.4.2+git20120612-8 | 1.4.2+git20120612-8 |
| openvswitch | openvswitch | >= 0 < 1.4.2+git20120612-8 | 1.4.2+git20120612-8 |
| openvswitch | openvswitch | >= 0 < 1.4.2+git20120612-8 | 1.4.2+git20120612-8 |
| openvswitch | openvswitch | >= 0 < 1.4.2+git20120612-8 | 1.4.2+git20120612-8 |
CVSS provenance
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
osv3.6LOW
vendor_debian3.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f9jx-2g6h-pw23: Open vSwitch 1
ghsa_unreviewed·2022-05-17
CVE-2012-3449 [LOW] GHSA-f9jx-2g6h-pw23: Open vSwitch 1
Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/pki/controllerca/incoming/ and (2) /var/lib/openvswitch/pki/switchca/incoming/, which allows local users to delete and overwrite arbitrary files.
OSV
CVE-2012-3449: Open vSwitch 1
osv·2012-08-07·CVSS 3.6
CVE-2012-3449 [LOW] CVE-2012-3449: Open vSwitch 1
Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/pki/controllerca/incoming/ and (2) /var/lib/openvswitch/pki/switchca/incoming/, which allows local users to delete and overwrite arbitrary files.
Debian
CVE-2012-3449: openvswitch - Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/...
vendor_debian·2012·CVSS 3.6
CVE-2012-3449 [LOW] CVE-2012-3449: openvswitch - Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/...
Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/pki/controllerca/incoming/ and (2) /var/lib/openvswitch/pki/switchca/incoming/, which allows local users to delete and overwrite arbitrary files.
Scope: local
bookworm: resolved (fixed in 1.4.2+git20120612-8)
bullseye: resolved (fixed in 1.4.2+git20120612-8)
forky: resolved (fixed in 1.4.2+git20120612-8)
sid: resolved (fixed in 1.4.2+git20120612-8)
trixie: resolved (fixed in 1.4.2+git20120612-8)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3449 openvswitch: creates world writable directories: /var/lib/openvswitch/pki/*ca/incoming/
bugzilla·2012-08-02·CVSS 3.6
CVE-2012-3449 [LOW] CVE-2012-3449 openvswitch: creates world writable directories: /var/lib/openvswitch/pki/*ca/incoming/
CVE-2012-3449 openvswitch: creates world writable directories: /var/lib/openvswitch/pki/*ca/incoming/
Andreas Beckmann [email protected] reports:
openvswitch-pki creates the following world writable directories during
installation:
drwx-wx-wx 2 root root 40 Aug 1 05:32 /var/lib/openvswitch/pki/controllerca/incoming
drwx-wx-wx 2 root root 40 Aug 1 05:32 /var/lib/openvswitch/pki/switchca/incoming
Even if an ordinary local user cannot list the contents of the
directory, he may correctly derive/guess filenames (unless they are
exclusively $(mktemp)) and delete and replace files in there.
I don't know how openvswitch-pki works, how it uses this directory,
what probelms could possibly arise out of this.
References:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=683665
Please note on F
Bugzilla
CVE-2012-3449 openvswitch: creates world writable directories: /var/lib/openvswitch/pki/*ca/incoming/ [fedora-all]
bugzilla·2012-08-02·CVSS 3.6
CVE-2012-3449 [LOW] CVE-2012-3449 openvswitch: creates world writable directories: /var/lib/openvswitch/pki/*ca/incoming/ [fedora-all]
CVE-2012-3449 openvswitch: creates world writable directories: /var/lib/openvswitch/pki/*ca/incoming/ [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedora
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=683665http://www.openwall.com/lists/oss-security/2012/08/02/6http://www.openwall.com/lists/oss-security/2012/08/03/6http://www.securityfocus.com/bid/54789http://www.securityfocus.com/bid/54794https://bugzilla.redhat.com/show_bug.cgi?id=845350https://exchange.xforce.ibmcloud.com/vulnerabilities/77417http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=683665http://www.openwall.com/lists/oss-security/2012/08/02/6http://www.openwall.com/lists/oss-security/2012/08/03/6http://www.securityfocus.com/bid/54789http://www.securityfocus.com/bid/54794https://bugzilla.redhat.com/show_bug.cgi?id=845350https://exchange.xforce.ibmcloud.com/vulnerabilities/77417
2012-08-07
Published