CVE Vulnerabilities

CVE-2012-2291

Published: Jan 21, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

EMC Avamar Client 4.x, 5.x, and 6.x on HP-UX and Mac OS X, and the EMC Avamar plugin 4.x, 5.x, and 6.x for Oracle, uses world-writable permissions for cache directories, which allows local users to gain privileges via an unspecified symlink attack.

Affected Software

NameVendorStart VersionEnd Version
AvamarEmc4.0 (including)4.0 (including)
AvamarEmc4.1 (including)4.1 (including)
AvamarEmc5.0 (including)5.0 (including)
AvamarEmc5.0-sp1 (including)5.0-sp1 (including)
AvamarEmc5.0-sp2 (including)5.0-sp2 (including)
AvamarEmc5.0.0-407 (including)5.0.0-407 (including)
AvamarEmc5.0.4-26 (including)5.0.4-26 (including)
AvamarEmc6.0 (including)6.0 (including)

References