CVE Vulnerabilities

CVE-2012-4417

Published: Nov 18, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.6 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:P
RedHat/V2
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.

Affected Software

NameVendorStart VersionEnd Version
GlusterfsGluster3.3.0 (including)3.3.0 (including)
Native Client for RHEL 5 for Red Hat StorageRedHatglusterfs-0:3.3.0.5rhs-37.el5*
Native Client for RHEL 6 for Red Hat StorageRedHatglusterfs-0:3.3.0.5rhs-37.el6*
Red Hat Storage 2.0RedHatglusterfs-0:3.3.0.5rhs-37.el6rhs*
Red Hat Storage 2.0RedHatsos-0:2.2-17.1.el6rhs*
GlusterfsUbuntulucid*
GlusterfsUbuntuoneiric*
GlusterfsUbuntuprecise*
GlusterfsUbuntuquantal*
GlusterfsUbunturaring*
GlusterfsUbuntusaucy*
GlusterfsUbuntuupstream*
GlusterfsUbuntuutopic*
GlusterfsUbuntuvivid*
GlusterfsUbuntuwily*

References