Vulnerability CVE-2012-3329


Published: 2012-12-19

Description:
IBM Advanced Settings Utility (ASU) through 3.62 and 3.70 through 9.21 and Bootable Media Creator (BoMC) through 2.30 and 3.00 through 9.21 on Linux allow local users to overwrite arbitrary files via a symlink attack on a (1) temporary file or (2) log file.

CVSS2 => (AV:L/AC:M/Au:N/C:N/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
3.3/10
4.9/10
3.4/10
Exploit range
Attack complexity
Authentication
Local
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
Partial
Affected software
IBM -> Advanced settings utility 
IBM -> Bootable media creator 

 References:
http://xforce.iss.net/xforce/xfdb/78044
http://www.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5092090

Copyright 2024, cxsecurity.com

 

Back to Top