CVE Vulnerabilities

CVE-2012-5638

Published: Dec 20, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.6 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:P
RedHat/V2
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The setup_logging function in log.h in SANLock uses world-writable permissions for /var/log/sanlock.log, which allows local users to overwrite the file content or bypass intended disk-quota restrictions via standard filesystem write operations.

Affected Software

NameVendorStart VersionEnd Version
SanlockOvirt- (including)- (including)
Native Client for RHEL 5 for Red Hat StorageRedHatglusterfs-0:3.3.0.7rhs-1.el5*
Native Client for RHEL 6 for Red Hat StorageRedHatglusterfs-0:3.3.0.7rhs-1.el6*
Red Hat Storage 2.0RedHatappliance-0:1.7.1-1.el6rhs*
Red Hat Storage 2.0RedHataugeas-0:0.9.0-1.el6*
Red Hat Storage 2.0RedHatglusterfs-0:3.3.0.7rhs-1.el6rhs*
Red Hat Storage 2.0RedHatgluster-swift-0:1.4.8-5.el6rhs*
Red Hat Storage 2.0RedHatlibvirt-0:0.9.10-21.el6_3.8*
Red Hat Storage 2.0RedHatrhn-client-tools-0:1.0.0-73.el6rhs*
Red Hat Storage 2.0RedHatsanlock-0:2.3-4.el6_3*
Red Hat Storage 2.0RedHatsos-0:2.2-17.2.el6rhs*
Red Hat Storage 2.0RedHatvdsm-0:4.9.6-20.el6rhs*
Red Hat Storage 2.0 ConsoleRedHatorg.ovirt.engine-root-0:2.0.techpreview1-4*
Red Hat Storage 2.0 ConsoleRedHatvdsm-0:4.9.6-20.el6rhs*
RHEV 3.X Hypervisor and Agents for RHEL-6RedHatsanlock-0:2.3-4.el6_3*
SanlockUbuntuartful*
SanlockUbuntuquantal*
SanlockUbunturaring*
SanlockUbuntusaucy*
SanlockUbuntuupstream*
SanlockUbuntuutopic*
SanlockUbuntuvivid*
SanlockUbuntuwily*
SanlockUbuntuyakkety*
SanlockUbuntuzesty*

References