PT-2013-1514 · Augeas+2 · Augeas+2
Vincent Danen
·
Published
2013-11-20
·
Updated
2019-04-22
·
CVE-2012-0787
CVSS v2.0
3.7
Low
| Vector | AV:L/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Augeas versions prior to 1.0.0
Description
The issue allows local users to overwrite arbitrary files and obtain sensitive information via a bind mount on certain files when using specific save options. This can occur when the
copy if rename fails is set and certain error conditions are met by the rename function. The affected files include the .augsave or destination file when using the backup save option, or the .augnew file when using the newfile save option.Recommendations
For versions prior to 1.0.0, update to version 1.0.0 or later to resolve the issue. As a temporary workaround, consider disabling the
clone file function in transfer.c until a patch is available. Restrict access to the copy if rename fails option to minimize the risk of exploitation. Avoid using the backup save option or the newfile save option with the clone file function until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Augeas
Centos
Red Hat