Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-6607

Опубликовано: 21 нояб. 2013
Источник: redhat
CVSS2: 3.3
EPSS Низкий

Описание

The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on a .augsave file in a backup save action, a different vector than CVE-2012-0786.

Отчет

Red Hat believes that the flaw described by this CVE never affected augeas and therefore we consider this CVE assignment as invalid. For further details, refer to: https://bugzilla.redhat.com/show_bug.cgi?id=1034243#c1

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6augeasNot affected
Red Hat Enterprise Linux 7augeasNot affected
Red Hat OpenStack Platform 3augeasNot affected
Red Hat OpenStack Platform 4augeasNot affected
Red Hat Storage 2.1augeasNot affected

Показывать по

Дополнительная информация

https://bugzilla.redhat.com/show_bug.cgi?id=1034243augeas: symlink attack on a .augsave file

EPSS

Процентиль: 14%
0.00046
Низкий

3.3 Low

CVSS2

Связанные уязвимости

ubuntu
около 12 лет назад

The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on a .augsave file in a backup save action, a different vector than CVE-2012-0786.

nvd
около 12 лет назад

The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on a .augsave file in a backup save action, a different vector than CVE-2012-0786.

debian
около 12 лет назад

The transform_save function in transform.c in Augeas before 1.0.0 allo ...

github
больше 3 лет назад

The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on a .augsave file in a backup save action, a different vector than CVE-2012-0786.

EPSS

Процентиль: 14%
0.00046
Низкий

3.3 Low

CVSS2

Уязвимость CVE-2012-6607