Bug 886364 (CVE-2012-5635)
Summary: | CVE-2012-5635 GlusterFS: insecure temporary file creation | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Kurt Seifried <kseifried> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | aavati, amarts, jrusnack, misc, rabhat, rhs-bugs, security-response-team, shaines, vbellur |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: |
Multiple insecure temporary file creation flaws were found in Red Hat Storage. A local user on the Red Hat Storage server could use these flaws to cause arbitrary files to be overwritten as the root user via a symbolic link attack.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2013-08-22 02:51:42 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 886365 | ||
Bug Blocks: | 886367 |
Description
Kurt Seifried
2012-12-12 06:35:11 UTC
*** Bug 894870 has been marked as a duplicate of this bug. *** *** Bug 894871 has been marked as a duplicate of this bug. *** *** Bug 894872 has been marked as a duplicate of this bug. *** Acknowledgements: These issues were discovered by Kurt Seifried of the Red Hat Security Response Team and Michael Scherer of the Red Hat Regional IT team. This issue has been addressed in following products: Red Hat Storage 2.0 Red Hat Storage 2.0 Console Native Client for RHEL 5 for Red Hat Storage Native Client for RHEL 6 for Red Hat Storage Via RHSA-2013:0691 https://rhn.redhat.com/errata/RHSA-2013-0691.html |