PT-2013-1514 · Augeas+2 · Augeas+2

Vincent Danen

·

Publicado

2013-11-20

·

Atualizado

2019-04-22

·

CVE-2012-0787

CVSS v2.0

3.7

Baixa

VetorAV:L/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Augeas versions prior to 1.0.0
Description The issue allows local users to overwrite arbitrary files and obtain sensitive information via a bind mount on certain files when using specific save options. This can occur when the copy if rename fails is set and certain error conditions are met by the rename function. The affected files include the .augsave or destination file when using the backup save option, or the .augnew file when using the newfile save option.
Recommendations For versions prior to 1.0.0, update to version 1.0.0 or later to resolve the issue. As a temporary workaround, consider disabling the clone file function in transfer.c until a patch is available. Restrict access to the copy if rename fails option to minimize the risk of exploitation. Avoid using the backup save option or the newfile save option with the clone file function until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CESA-2013_1537
CVE-2012-0787
DLA-28-1
MGASA-2014-0058
RHSA-2013:1537
RHSA-2013_1537

Produtos afetados

Augeas
Centos
Red Hat