CVE-2012-4417
published 2012-11-18CVE-2012-4417: GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to overwrite arbitrary files via a symlink attack on temporary files with…
PriorityP411low3.6CVSS 2.0
AVLACLAuNCNIPAP
EPSS
0.34%
25.8th percentile
GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glusterfs | < glusterfs 3.5.0-1 (bookworm) | glusterfs 3.5.0-1 (bookworm) |
| debian | glusterfs | < glusterfs 3.2.7-5 (bookworm) | glusterfs 3.2.7-5 (bookworm) |
| gluster | glusterfs | — | — |
| gluster | glusterfs | >= 0 < 3.2.7-5 | 3.2.7-5 |
| gluster | glusterfs | >= 0 < 3.5.0-1 | 3.5.0-1 |
| gluster | glusterfs | >= 0 < 3.2.7-5 | 3.2.7-5 |
| gluster | glusterfs | >= 0 < 3.5.0-1 | 3.5.0-1 |
| gluster | glusterfs | >= 0 < 3.2.7-5 | 3.2.7-5 |
| gluster | glusterfs | >= 0 < 3.5.0-1 | 3.5.0-1 |
| gluster | glusterfs | >= 0 < 3.2.7-5 | 3.2.7-5 |
| gluster | glusterfs | >= 0 < 3.5.0-1 | 3.5.0-1 |
| redhat | storage_management_console | — | — |
| redhat | storage_server | — | — |
CVSS provenance
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
osv3.6LOW
vendor_debian3.6LOW
vendor_redhat3.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w74w-4wpp-3vmm: The GlusterFS functionality in Red Hat Storage Management Console 2
ghsa_unreviewed·2022-05-17·CVSS 3.6
CVE-2012-5635 [LOW] GHSA-w74w-4wpp-3vmm: The GlusterFS functionality in Red Hat Storage Management Console 2
The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and possibly other vectors, different vulnerabilities than CVE-2012-4417.
GHSA
GHSA-f7v9-7368-5x59: GlusterFS 3
ghsa_unreviewed·2022-05-17
CVE-2012-4417 [LOW] GHSA-f7v9-7368-5x59: GlusterFS 3
GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.
OSV
CVE-2012-5635: The GlusterFS functionality in Red Hat Storage Management Console 2
osv·2013-04-09·CVSS 3.6
CVE-2012-5635 [LOW] CVE-2012-5635: The GlusterFS functionality in Red Hat Storage Management Console 2
The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and possibly other vectors, different vulnerabilities than CVE-2012-4417.
OSV
CVE-2012-4417: GlusterFS 3
osv·2012-11-18·CVSS 3.6
CVE-2012-4417 [LOW] CVE-2012-4417: GlusterFS 3
GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.
Red Hat
GlusterFS: insecure temporary file creation
vendor_redhat·2013-03-28·CVSS 3.6
CVE-2012-5635 [LOW] CWE-377 GlusterFS: insecure temporary file creation
GlusterFS: insecure temporary file creation
The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and possibly other vectors, different vulnerabilities than CVE-2012-4417.
Multiple insecure temporary file creation flaws were found in Red Hat Storage. A local user on the Red Hat Storage server could use these flaws to cause arbitrary files to be overwritten as the root user via a symbolic link attack.
Red Hat
GlusterFS: insecure temporary file creation
vendor_redhat·2012-11-12·CVSS 3.6
CVE-2012-4417 [LOW] CWE-377 GlusterFS: insecure temporary file creation
GlusterFS: insecure temporary file creation
GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.
Debian
CVE-2012-5635: glusterfs - The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Cl...
vendor_debian·2012·CVSS 3.6
CVE-2012-5635 [LOW] CVE-2012-5635: glusterfs - The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Cl...
The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and possibly other vectors, different vulnerabilities than CVE-2012-4417.
Scope: local
bookworm: resolved (fixed in 3.5.0-1)
bullseye: resolved (fixed in 3.5.0-1)
forky: resolved (fixed in 3.5.0-1)
sid: resolved (fixed in 3.5.0-1)
trixie: resolved (fixed in 3.5.0-1)
Debian
CVE-2012-4417: glusterfs - GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to ov...
vendor_debian·2012·CVSS 3.6
CVE-2012-4417 [LOW] CVE-2012-4417: glusterfs - GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to ov...
GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.
Scope: local
bookworm: resolved (fixed in 3.2.7-5)
bullseye: resolved (fixed in 3.2.7-5)
forky: resolved (fixed in 3.2.7-5)
sid: resolved (fixed in 3.2.7-5)
trixie: resolved (fixed in 3.2.7-5)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-5635 GlusterFS: insecure temporary file creation
bugzilla·2012-12-12·CVSS 3.6
CVE-2012-5635 [LOW] CVE-2012-5635 GlusterFS: insecure temporary file creation
CVE-2012-5635 GlusterFS: insecure temporary file creation
Following the fixing of several /tmp/ flaws in CVE-2012-4417 we have the
remaining issues in Gluster reported by Kurt Seifried ([email protected]):
This issue was previously not reported:
This should probably use /var/run/gluster/glusterdump.%d.options
tests/volume.rc: rm -f /tmp/glusterdump.$mount_pid.dump.* 2>/dev/null
tests/volume.rc: fname=$(ls /tmp | grep -E "glusterdump.$mount_pid.dump.*")
tests/volume.rc: echo /tmp/$fname
This issue was previously not reported:
This should use mktemp
Also this should use cp instead of mv so you don't lose SELinux context when
copying the file back to /etc/samba/smb.conf which might break Samba
extras/hook-scripts/S30samba-stop.sh: cp /etc/samba/smb.conf /tmp/smb.conf
extras/hook-scrip
Bugzilla
CVE-2012-4417 GlusterFS: insecure temporary file creation [fedora-all]
bugzilla·2012-11-12·CVSS 3.6
CVE-2012-4417 [LOW] CVE-2012-4417 GlusterFS: insecure temporary file creation [fedora-all]
CVE-2012-4417 GlusterFS: insecure temporary file creation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects mu
Bugzilla
CVE-2012-4417 GlusterFS: insecure temporary file creation [epel-all]
bugzilla·2012-11-12·CVSS 3.6
CVE-2012-4417 [LOW] CVE-2012-4417 GlusterFS: insecure temporary file creation [epel-all]
CVE-2012-4417 GlusterFS: insecure temporary file creation [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects
Bugzilla
CVE-2012-4417 GlusterFS: insecure temporary file creation
bugzilla·2012-09-11·CVSS 3.6
CVE-2012-4417 [LOW] CVE-2012-4417 GlusterFS: insecure temporary file creation
CVE-2012-4417 GlusterFS: insecure temporary file creation
Jim Meyering ([email protected]) of Red Hat reports:
glusterfs writes to predictably-named files in /tmp using the PID and other
non random or easily guessed information to create file names.
libglusterfs/src/statedump.c
gf_proc_dump_open (char *dump_dir, char *brickname)
{
char path[PATH_MAX] = {0,};
int dump_fd = -1;
snprintf (path, sizeof (path), "%s/%s.%d.dump", (dump_dir ?
dump_dir : "/tmp"), brickname, getpid());
...
gf_proc_dump_options_init ()
{
int ret = -1;
FILE *fp = NULL;
char buf[256];
char dumpbuf[GF_DUMP_MAX_BUF_LEN];
char *key = NULL, *value = NULL;
char *saveptr = NULL;
char dump_option_file[PATH_MAX];
snprintf (dump_option_file, sizeof (dump_option_file),
"/tmp/glusterdump.%d.options", getpid ());
Discu
arXiv
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
arxiv_fulltext·2022-04-26
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
## Abstract
This paper presents a systematic study on the security of modern file systems,
following a vulnerability-centric perspective. Specifically,
we collected 377 file system vulnerabilities committed to the CVE database in the past 20 years.
We characterize them from four dimensions that include why the vulnerabilities appear,
how the vulnerabilities can be exploited, what consequences can arise,
and how the vulnerabilities are fixed. This way, we build a deep understanding of
the attack surfaces faced by file systems, the threats imposed by the attack surfaces,
and the good and bad practices in mitigating the attacks in file systems. We envision that our study
will bring insights toward
http://rhn.redhat.com/errata/RHSA-2012-1456.htmlhttp://www.securityfocus.com/bid/56522http://www.securitytracker.com/id?1027756https://bugzilla.redhat.com/show_bug.cgi?id=856341https://exchange.xforce.ibmcloud.com/vulnerabilities/80074http://rhn.redhat.com/errata/RHSA-2012-1456.htmlhttp://www.securityfocus.com/bid/56522http://www.securitytracker.com/id?1027756https://bugzilla.redhat.com/show_bug.cgi?id=856341https://exchange.xforce.ibmcloud.com/vulnerabilities/80074
2012-11-18
Published