CVE-2012-5635
published 2013-04-09CVE-2012-5635: The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a…
PriorityP411low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.32%
23.7th percentile
The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and possibly other vectors, different vulnerabilities than CVE-2012-4417.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glusterfs | < glusterfs 3.5.0-1 (bookworm) | glusterfs 3.5.0-1 (bookworm) |
| gluster | glusterfs | >= 0 < 3.5.0-1 | 3.5.0-1 |
| gluster | glusterfs | >= 0 < 3.5.0-1 | 3.5.0-1 |
| gluster | glusterfs | >= 0 < 3.5.0-1 | 3.5.0-1 |
| gluster | glusterfs | >= 0 < 3.5.0-1 | 3.5.0-1 |
| redhat | storage_management_console | — | — |
| redhat | storage_server | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv3.6LOW
vendor_debian3.6LOW
vendor_redhat3.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w74w-4wpp-3vmm: The GlusterFS functionality in Red Hat Storage Management Console 2
ghsa_unreviewed·2022-05-17·CVSS 3.6
CVE-2012-5635 [LOW] GHSA-w74w-4wpp-3vmm: The GlusterFS functionality in Red Hat Storage Management Console 2
The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and possibly other vectors, different vulnerabilities than CVE-2012-4417.
OSV
CVE-2012-5635: The GlusterFS functionality in Red Hat Storage Management Console 2
osv·2013-04-09·CVSS 3.6
CVE-2012-5635 [LOW] CVE-2012-5635: The GlusterFS functionality in Red Hat Storage Management Console 2
The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and possibly other vectors, different vulnerabilities than CVE-2012-4417.
Red Hat
GlusterFS: insecure temporary file creation
vendor_redhat·2013-03-28·CVSS 3.6
CVE-2012-5635 [LOW] CWE-377 GlusterFS: insecure temporary file creation
GlusterFS: insecure temporary file creation
The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and possibly other vectors, different vulnerabilities than CVE-2012-4417.
Multiple insecure temporary file creation flaws were found in Red Hat Storage. A local user on the Red Hat Storage server could use these flaws to cause arbitrary files to be overwritten as the root user via a symbolic link attack.
Debian
CVE-2012-5635: glusterfs - The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Cl...
vendor_debian·2012·CVSS 3.6
CVE-2012-5635 [LOW] CVE-2012-5635: glusterfs - The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Cl...
The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and possibly other vectors, different vulnerabilities than CVE-2012-4417.
Scope: local
bookworm: resolved (fixed in 3.5.0-1)
bullseye: resolved (fixed in 3.5.0-1)
forky: resolved (fixed in 3.5.0-1)
sid: resolved (fixed in 3.5.0-1)
trixie: resolved (fixed in 3.5.0-1)
No detection rules found.
No public exploits indexed.
2013-04-09
Published