CVE-2012-5530
published 2012-11-29CVE-2012-5530: The (1) pcmd and (2) pmlogger init scripts in Performance Co-Pilot (PCP) before 3.6.10 allow local users to overwrite arbitrary files via a symlink attack on a…
PriorityP47low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.37%
29.2th percentile
The (1) pcmd and (2) pmlogger init scripts in Performance Co-Pilot (PCP) before 3.6.10 allow local users to overwrite arbitrary files via a symlink attack on a /var/tmp/##### temporary file.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pcp | < pcp 3.7.1 (bookworm) | pcp 3.7.1 (bookworm) |
| opensuse | pcp | >= 0 < 3.7.1 | 3.7.1 |
| opensuse | pcp | >= 0 < 3.7.1 | 3.7.1 |
| opensuse | pcp | >= 0 < 3.7.1 | 3.7.1 |
| opensuse | pcp | >= 0 < 3.7.1 | 3.7.1 |
| sgi | performance_co-pilot | <= 3.6.9 | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv2.1LOW
vendor_debian2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5rxm-r7q9-4x4v: The (1) pcmd and (2) pmlogger init scripts in Performance Co-Pilot (PCP) before 3
ghsa_unreviewed·2022-05-17
CVE-2012-5530 [LOW] GHSA-5rxm-r7q9-4x4v: The (1) pcmd and (2) pmlogger init scripts in Performance Co-Pilot (PCP) before 3
The (1) pcmd and (2) pmlogger init scripts in Performance Co-Pilot (PCP) before 3.6.10 allow local users to overwrite arbitrary files via a symlink attack on a /var/tmp/##### temporary file.
OSV
CVE-2012-5530: The (1) pcmd and (2) pmlogger init scripts in Performance Co-Pilot (PCP) before 3
osv·2012-11-29·CVSS 2.1
CVE-2012-5530 [LOW] CVE-2012-5530: The (1) pcmd and (2) pmlogger init scripts in Performance Co-Pilot (PCP) before 3
The (1) pcmd and (2) pmlogger init scripts in Performance Co-Pilot (PCP) before 3.6.10 allow local users to overwrite arbitrary files via a symlink attack on a /var/tmp/##### temporary file.
Debian
CVE-2012-5530: pcp - The (1) pcmd and (2) pmlogger init scripts in Performance Co-Pilot (PCP) before ...
vendor_debian·2012·CVSS 2.1
CVE-2012-5530 [LOW] CVE-2012-5530: pcp - The (1) pcmd and (2) pmlogger init scripts in Performance Co-Pilot (PCP) before ...
The (1) pcmd and (2) pmlogger init scripts in Performance Co-Pilot (PCP) before 3.6.10 allow local users to overwrite arbitrary files via a symlink attack on a /var/tmp/##### temporary file.
Scope: local
bookworm: resolved (fixed in 3.7.1)
bullseye: resolved (fixed in 3.7.1)
forky: resolved (fixed in 3.7.1)
sid: resolved (fixed in 3.7.1)
trixie: resolved (fixed in 3.7.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-5530 pcp: Insecure temporary file use flaws [epel-all]
bugzilla·2012-11-19·CVSS 2.1
CVE-2012-5530 [LOW] CVE-2012-5530 pcp: Insecure temporary file use flaws [epel-all]
CVE-2012-5530 pcp: Insecure temporary file use flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects mult
Bugzilla
CVE-2012-5530 pcp: Insecure temporary file use flaws [fedora-all]
bugzilla·2012-11-19·CVSS 2.1
CVE-2012-5530 [LOW] CVE-2012-5530 pcp: Insecure temporary file use flaws [fedora-all]
CVE-2012-5530 pcp: Insecure temporary file use flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multipl
Bugzilla
CVE-2012-5530 pcp: Insecure temporary file use flaws
bugzilla·2012-11-12·CVSS 2.1
CVE-2012-5530 [LOW] CVE-2012-5530 pcp: Insecure temporary file use flaws
CVE-2012-5530 pcp: Insecure temporary file use flaws
A security flaw was found in the way Performance Co-Pilot (PCP), a framework and services to support system-level performance monitoring and performance management, performed management of its temporary files used by various services from the suite. A local attacker could use this flaw to conduct symbolic link attacks (alter or remove different system files, accessible with the privileges of the user running the PCP suite, than it was originally intended).
References:
[1] https://bugzilla.novell.com/show_bug.cgi?id=782967 (private)
Discussion:
Preliminary embargo date for this issue has been set up to this Friday, 2012-11-16.
---
Acknowledgements:
Red Hat would like to thank SUSE Security Team for reporting this issue. SUSE Securi
http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00024.htmlhttp://www.securityfocus.com/bid/56656https://bugzilla.novell.com/show_bug.cgi?id=782967https://bugzilla.redhat.com/show_bug.cgi?id=875842http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00024.htmlhttp://www.securityfocus.com/bid/56656https://bugzilla.novell.com/show_bug.cgi?id=782967https://bugzilla.redhat.com/show_bug.cgi?id=875842
2012-11-29
Published