Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-6607

Опубликовано: 21 нояб. 2013
Источник: redhat
CVSS2: 3.3
EPSS Низкий

Описание

The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on a .augsave file in a backup save action, a different vector than CVE-2012-0786.

Отчет

Red Hat believes that the flaw described by this CVE never affected augeas and therefore we consider this CVE assignment as invalid. For further details, refer to: https://bugzilla.redhat.com/show_bug.cgi?id=1034243#c1

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6augeasNot affected
Red Hat Enterprise Linux 7augeasNot affected
Red Hat OpenStack Platform 3augeasNot affected
Red Hat OpenStack Platform 4augeasNot affected
Red Hat Storage 2augeasNot affected

Показывать по

Дополнительная информация

https://bugzilla.redhat.com/show_bug.cgi?id=1034243augeas: symlink attack on a .augsave file

EPSS

Процентиль: 29%
0.00365
Низкий

3.3 Low

CVSS2

Связанные уязвимости

ubuntu
больше 12 лет назад

The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on a .augsave file in a backup save action, a different vector than CVE-2012-0786.

nvd
больше 12 лет назад

The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on a .augsave file in a backup save action, a different vector than CVE-2012-0786.

debian
больше 12 лет назад

The transform_save function in transform.c in Augeas before 1.0.0 allo ...

github
около 4 лет назад

The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on a .augsave file in a backup save action, a different vector than CVE-2012-0786.

EPSS

Процентиль: 29%
0.00365
Низкий

3.3 Low

CVSS2