PT-2012-4653 · Ibm · Ibm Bootable Media Creator+1

Published

2012-12-19

·

Updated

2017-08-29

·

CVE-2012-3329

CVSS v2.0

3.3

Low

VectorAV:L/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions IBM Advanced Settings Utility (ASU) versions 3.62 and 3.70 through 9.21 IBM Bootable Media Creator (BoMC) versions 2.30 and 3.00 through 9.21
Description The issue allows local users to overwrite arbitrary files via a symlink attack on a temporary file or log file.
Recommendations For IBM Advanced Settings Utility (ASU) versions 3.62 and 3.70 through 9.21, consider restricting access to temporary and log files to prevent arbitrary file overwrites. For IBM Bootable Media Creator (BoMC) versions 2.30 and 3.00 through 9.21, consider restricting access to temporary and log files to prevent arbitrary file overwrites. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-3329

Affected Products

Ibm Advanced Settings Utility
Ibm Bootable Media Creator