CVE-2012-3500
published 2012-10-01CVE-2012-3500: scripts/annotate-output.sh in devscripts before 2.12.2, as used in rpmdevtools before 8.3, allows local users to modify arbitrary files via a symlink attack on…
PriorityP410low1.2CVSS 2.0
AVLACHAuNCNIPAN
EPSS
0.27%
18.8th percentile
scripts/annotate-output.sh in devscripts before 2.12.2, as used in rpmdevtools before 8.3, allows local users to modify arbitrary files via a symlink attack on the temporary (1) standard output or (2) standard error output file.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | devscripts | < devscripts 2.12.2 (bookworm) | devscripts 2.12.2 (bookworm) |
| devscripts_devel_team | devscripts | <= 2.12.1 | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | >= 0 < 2.12.2 | 2.12.2 |
| devscripts_devel_team | devscripts | >= 0 < 2.12.2 | 2.12.2 |
| devscripts_devel_team | devscripts | >= 0 < 2.12.2 | 2.12.2 |
| devscripts_devel_team | devscripts | >= 0 < 2.12.2 | 2.12.2 |
CVSS provenance
nvdv2.01.2LOWAV:L/AC:H/Au:N/C:N/I:P/A:N
osv1.2LOW
vendor_ubuntu9.3CRITICAL
vendor_debian1.2LOW
vendor_redhat1.2LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
devscripts vulnerabilities
vendor_ubuntu·2012-10-02·CVSS 9.3
CVE-2012-0212 [CRITICAL] devscripts vulnerabilities
Title: devscripts vulnerabilities
Summary: Several security issues were fixed in devscripts.
Raphael Geissert discovered that the debdiff.pl tool incorrectly handled
shell metacharacters. If a user or automated system were tricked into
processing a specially crafted filename, a remote attacher could possibly
execute arbitrary code. (CVE-2012-0212)
Raphael Geissert discovered that the dscverify tool incorrectly escaped
arguments to external commands. If a user or automated system were tricked
into processing specially crafted files, a remote attacher could possibly
execute arbitrary code. (CVE-2012-2240)
Raphael Geissert discovered that the dget tool incorrectly performed input
validation. If a user or automated system were tricked into processing
specially crafted files, a remote attac
Red Hat
rpmdevtools: TOCTOU race condition in annotate-output
vendor_redhat·2012-08-31·CVSS 1.2
CVE-2012-3500 [LOW] CWE-367 rpmdevtools: TOCTOU race condition in annotate-output
rpmdevtools: TOCTOU race condition in annotate-output
scripts/annotate-output.sh in devscripts before 2.12.2, as used in rpmdevtools before 8.3, allows local users to modify arbitrary files via a symlink attack on the temporary (1) standard output or (2) standard error output file.
Package: rpmdevtools (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2012-3500: devscripts - scripts/annotate-output.sh in devscripts before 2.12.2, as used in rpmdevtools b...
vendor_debian·2012·CVSS 1.2
CVE-2012-3500 [LOW] CVE-2012-3500: devscripts - scripts/annotate-output.sh in devscripts before 2.12.2, as used in rpmdevtools b...
scripts/annotate-output.sh in devscripts before 2.12.2, as used in rpmdevtools before 8.3, allows local users to modify arbitrary files via a symlink attack on the temporary (1) standard output or (2) standard error output file.
Scope: local
bookworm: resolved (fixed in 2.12.2)
bullseye: resolved (fixed in 2.12.2)
forky: resolved (fixed in 2.12.2)
sid: resolved (fixed in 2.12.2)
trixie: resolved (fixed in 2.12.2)
GHSA
GHSA-8w6p-f8f6-wxp6: scripts/annotate-output
ghsa_unreviewed·2022-05-17
CVE-2012-3500 [LOW] CWE-362 GHSA-8w6p-f8f6-wxp6: scripts/annotate-output
scripts/annotate-output.sh in devscripts before 2.12.2, as used in rpmdevtools before 8.3, allows local users to modify arbitrary files via a symlink attack on the temporary (1) standard output or (2) standard error output file.
OSV
CVE-2012-3500: scripts/annotate-output
osv·2012-10-01·CVSS 1.2
CVE-2012-3500 [LOW] CVE-2012-3500: scripts/annotate-output
scripts/annotate-output.sh in devscripts before 2.12.2, as used in rpmdevtools before 8.3, allows local users to modify arbitrary files via a symlink attack on the temporary (1) standard output or (2) standard error output file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3500 rpmdevtools: TOCTOU race condition in annotate-output [fedora-all]
bugzilla·2012-08-31·CVSS 1.2
CVE-2012-3500 [LOW] CVE-2012-3500 rpmdevtools: TOCTOU race condition in annotate-output [fedora-all]
CVE-2012-3500 rpmdevtools: TOCTOU race condition in annotate-output [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=sec
Bugzilla
CVE-2012-3500 rpmdevtools: TOCTOU race condition in annotate-output
bugzilla·2012-08-14·CVSS 1.2
CVE-2012-3500 [LOW] CVE-2012-3500 rpmdevtools: TOCTOU race condition in annotate-output
CVE-2012-3500 rpmdevtools: TOCTOU race condition in annotate-output
A TOCTOU race condition was found in the way 'annotate-output' (used to execute a program annotating the output linewise with time and stream) tool of rpmdevtools, a suite of scripts and (X)Emacs support files to aid in development of RPM packages, performed management of its temporary files used for standard output and standard error output. A local attacker could use this flaw to conduct symbolic link attacks, possibly leading to their ability in an unauthorized way to alter files belonging to the user running the 'annotate-output' tool.
Issue found by Jim Meyering of Red Hat.
Discussion:
This issue affects the version of the rpmdevtools package, as shipped with
Red Hat Enterprise Linux 6.
--
This issue affects th
http://anonscm.debian.org/gitweb/?p=devscripts/devscripts.git%3Ba=commit%3Bh=4d23a5e6c90f7a37b0972b30f5d31dce97a93eb0http://git.fedorahosted.org/cgit/rpmdevtools.git/commit/?id=90b4400c2ab2e80cecfd8dfdf031536376ed2cdbhttp://lists.fedoraproject.org/pipermail/package-announce/2012-September/086138.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-September/086159.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-September/087335.htmlhttp://lists.opensuse.org/opensuse-updates/2012-11/msg00000.htmlhttp://secunia.com/advisories/50600http://www.debian.org/security/2012/dsa-2549http://www.mandriva.com/security/advisories?name=MDVSA-2013:123http://www.openwall.com/lists/oss-security/2012/08/31/7http://www.securityfocus.com/bid/55358http://www.ubuntu.com/usn/USN-1593-1https://bugzilla.redhat.com/show_bug.cgi?id=848022https://exchange.xforce.ibmcloud.com/vulnerabilities/78230https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-0316http://anonscm.debian.org/gitweb/?p=devscripts/devscripts.git%3Ba=commit%3Bh=4d23a5e6c90f7a37b0972b30f5d31dce97a93eb0http://git.fedorahosted.org/cgit/rpmdevtools.git/commit/?id=90b4400c2ab2e80cecfd8dfdf031536376ed2cdbhttp://lists.fedoraproject.org/pipermail/package-announce/2012-September/086138.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-September/086159.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-September/087335.htmlhttp://lists.opensuse.org/opensuse-updates/2012-11/msg00000.htmlhttp://secunia.com/advisories/50600http://www.debian.org/security/2012/dsa-2549http://www.mandriva.com/security/advisories?name=MDVSA-2013:123http://www.openwall.com/lists/oss-security/2012/08/31/7http://www.securityfocus.com/bid/55358http://www.ubuntu.com/usn/USN-1593-1https://bugzilla.redhat.com/show_bug.cgi?id=848022https://exchange.xforce.ibmcloud.com/vulnerabilities/78230https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-0316
2012-10-01
Published