CVE Vulnerabilities

CVE-2012-2291

Published: Jan 21, 2013 | Modified: Jan 22, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

EMC Avamar Client 4.x, 5.x, and 6.x on HP-UX and Mac OS X, and the EMC Avamar plugin 4.x, 5.x, and 6.x for Oracle, uses world-writable permissions for cache directories, which allows local users to gain privileges via an unspecified symlink attack.

Affected Software

Name Vendor Start Version End Version
Avamar Emc 4.0 (including) 4.0 (including)
Avamar Emc 4.1 (including) 4.1 (including)
Avamar Emc 5.0 (including) 5.0 (including)
Avamar Emc 5.0-sp1 (including) 5.0-sp1 (including)
Avamar Emc 5.0-sp2 (including) 5.0-sp2 (including)
Avamar Emc 5.0.0-407 (including) 5.0.0-407 (including)
Avamar Emc 5.0.4-26 (including) 5.0.4-26 (including)
Avamar Emc 6.0 (including) 6.0 (including)

References