CVE Vulnerabilities

CVE-2012-3292

Published: Jun 07, 2012 | Modified: Sep 07, 2012
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.6 HIGH
AV:N/AC:H/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The GridFTP in Globus Toolkit (GT) before 5.2.2, when certain autoconf macros are defined, does not properly check the return value from the getpwnam_r function, which might allow remote attackers to gain privileges by logging in with a user that does not exist, which causes GridFTP to run as the last user in the password file.

Affected Software

Name Vendor Start Version End Version
Globus_toolkit Globus * 5.2.1 (including)
Globus_toolkit Globus 2.0 (including) 2.0 (including)
Globus_toolkit Globus 2.2 (including) 2.2 (including)
Globus_toolkit Globus 2.4.3 (including) 2.4.3 (including)
Globus_toolkit Globus 3.0.2 (including) 3.0.2 (including)
Globus_toolkit Globus 3.2.1 (including) 3.2.1 (including)
Globus_toolkit Globus 4.0.0 (including) 4.0.0 (including)
Globus_toolkit Globus 4.0.1 (including) 4.0.1 (including)
Globus_toolkit Globus 4.0.2 (including) 4.0.2 (including)
Globus_toolkit Globus 4.0.3 (including) 4.0.3 (including)
Globus_toolkit Globus 4.0.4 (including) 4.0.4 (including)
Globus_toolkit Globus 4.0.5 (including) 4.0.5 (including)
Globus_toolkit Globus 4.0.6 (including) 4.0.6 (including)
Globus_toolkit Globus 4.0.7 (including) 4.0.7 (including)
Globus_toolkit Globus 4.0.8 (including) 4.0.8 (including)
Globus_toolkit Globus 4.2.0 (including) 4.2.0 (including)
Globus_toolkit Globus 4.2.1 (including) 4.2.1 (including)
Globus_toolkit Globus 5.0.0 (including) 5.0.0 (including)
Globus_toolkit Globus 5.0.1 (including) 5.0.1 (including)
Globus_toolkit Globus 5.0.2 (including) 5.0.2 (including)
Globus_toolkit Globus 5.0.3 (including) 5.0.3 (including)
Globus_toolkit Globus 5.0.4 (including) 5.0.4 (including)
Globus_toolkit Globus 5.0.5 (including) 5.0.5 (including)
Globus_toolkit Globus 5.2.0 (including) 5.2.0 (including)
Globus-gridftp-server Ubuntu lucid *
Globus-gridftp-server Ubuntu natty *
Globus-gridftp-server Ubuntu oneiric *
Globus-gridftp-server Ubuntu precise *
Globus-gridftp-server Ubuntu upstream *
Globus-gridftp-server-control Ubuntu lucid *
Globus-gridftp-server-control Ubuntu natty *
Globus-gridftp-server-control Ubuntu oneiric *
Globus-gridftp-server-control Ubuntu precise *
Globus-gridftp-server-control Ubuntu upstream *

References