PT-2013-1514 · Augeas+2 · Augeas+2

Vincent Danen

·

Published

2013-11-20

·

Updated

2019-04-22

·

CVE-2012-0787

CVSS v2.0

3.7

Low

VectorAV:L/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Augeas versions prior to 1.0.0
Description The issue allows local users to overwrite arbitrary files and obtain sensitive information via a bind mount on certain files when using specific save options. This can occur when the copy if rename fails is set and certain error conditions are met by the rename function. The affected files include the .augsave or destination file when using the backup save option, or the .augnew file when using the newfile save option.
Recommendations For versions prior to 1.0.0, update to version 1.0.0 or later to resolve the issue. As a temporary workaround, consider disabling the clone file function in transfer.c until a patch is available. Restrict access to the copy if rename fails option to minimize the risk of exploitation. Avoid using the backup save option or the newfile save option with the clone file function until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CESA-2013_1537
CVE-2012-0787
DLA-28-1
MGASA-2014-0058
RHSA-2013:1537
RHSA-2013_1537

Affected Products

Augeas
Centos
Red Hat