CVE-2012-4417
published 2012-11-18CVE-2012-4417: GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to overwrite arbitrary files via a symlink attack on temporary files with…
low3.6CVSS 3.1
AVLACLAuNCNIPAP
GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glusterfs | < glusterfs 3.5.0-1 (bookworm) | glusterfs 3.5.0-1 (bookworm) |
| debian | glusterfs | < glusterfs 3.2.7-5 (bookworm) | glusterfs 3.2.7-5 (bookworm) |
| gluster | glusterfs | — | — |
| gluster | glusterfs | >= 0 < 3.2.7-5 | 3.2.7-5 |
| gluster | glusterfs | >= 0 < 3.5.0-1 | 3.5.0-1 |
| gluster | glusterfs | >= 0 < 3.2.7-5 | 3.2.7-5 |
| gluster | glusterfs | >= 0 < 3.5.0-1 | 3.5.0-1 |
| gluster | glusterfs | >= 0 < 3.2.7-5 | 3.2.7-5 |
| gluster | glusterfs | >= 0 < 3.5.0-1 | 3.5.0-1 |
| gluster | glusterfs | >= 0 < 3.2.7-5 | 3.2.7-5 |
| gluster | glusterfs | >= 0 < 3.5.0-1 | 3.5.0-1 |
| redhat | storage_management_console | — | — |
| redhat | storage_server | — | — |
CVSS provenance
nvd3.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
osv3.6LOW