CVE-2012-5635

Source
https://nvd.nist.gov/vuln/detail/CVE-2012-5635
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2012-5635.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2012-5635
Related
Published
2013-04-09T20:55:01Z
Modified
2024-11-21T01:45:00Z
Summary
[none]
Details

The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and possibly other vectors, different vulnerabilities than CVE-2012-4417.

References

Affected packages

Debian:11 / glusterfs

Package

Name
glusterfs
Purl
pkg:deb/debian/glusterfs?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.5.0-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12 / glusterfs

Package

Name
glusterfs
Purl
pkg:deb/debian/glusterfs?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.5.0-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:13 / glusterfs

Package

Name
glusterfs
Purl
pkg:deb/debian/glusterfs?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.5.0-1

Ecosystem specific

{
    "urgency": "unimportant"
}