CVE Vulnerabilities

CVE-2012-5635

Published: Apr 09, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and possibly other vectors, different vulnerabilities than CVE-2012-4417.

Affected Software

NameVendorStart VersionEnd Version
GlusterfsGluster- (including)- (including)
Storage_management_consoleRedhat2.0 (including)2.0 (including)
Storage_native_clientRedhat- (including)- (including)
Storage_serverRedhat2.0 (including)2.0 (including)
Native Client for RHEL 5 for Red Hat StorageRedHatglusterfs-0:3.3.0.7rhs-1.el5*
Native Client for RHEL 6 for Red Hat StorageRedHatglusterfs-0:3.3.0.7rhs-1.el6*
Red Hat Storage 2.0RedHatappliance-0:1.7.1-1.el6rhs*
Red Hat Storage 2.0RedHataugeas-0:0.9.0-1.el6*
Red Hat Storage 2.0RedHatglusterfs-0:3.3.0.7rhs-1.el6rhs*
Red Hat Storage 2.0RedHatgluster-swift-0:1.4.8-5.el6rhs*
Red Hat Storage 2.0RedHatlibvirt-0:0.9.10-21.el6_3.8*
Red Hat Storage 2.0RedHatrhn-client-tools-0:1.0.0-73.el6rhs*
Red Hat Storage 2.0RedHatsanlock-0:2.3-4.el6_3*
Red Hat Storage 2.0RedHatsos-0:2.2-17.2.el6rhs*
Red Hat Storage 2.0RedHatvdsm-0:4.9.6-20.el6rhs*
Red Hat Storage 2.0 ConsoleRedHatorg.ovirt.engine-root-0:2.0.techpreview1-4*
Red Hat Storage 2.0 ConsoleRedHatvdsm-0:4.9.6-20.el6rhs*
GlusterfsUbuntulucid*
GlusterfsUbuntuoneiric*
GlusterfsUbuntuprecise*
GlusterfsUbuntuquantal*
GlusterfsUbunturaring*
GlusterfsUbuntusaucy*
GlusterfsUbuntuupstream*
GlusterfsUbuntuutopic*
GlusterfsUbuntuvivid*
GlusterfsUbuntuwily*

References