Vulnerability CVE-2012-3537


Published: 2012-09-05   Modified: 2012-09-06

Description:
The Crowbar Ohai plugin (chef/cookbooks/ohai/files/default/plugins/crowbar.rb) in the Deployer Barclamp in Crowbar, possibly 1.4 and earlier, allows local users to execute arbitrary shell commands via vectors related to "insecure handling of tmp files" and predictable file names.

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.6/10
6.4/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
DELL -> Crowbar 

 References:
https://github.com/SUSE-Cloud/barclamp-deployer/commit/b6454268a067fc77ff5de82057b5b53b3cc38b87
https://github.com/SUSE-Cloud/barclamp-deployer/commit/5ea8d4ddaa4cb1ce834d36889f0fe7ac0d617bc8
https://github.com/dellcloudedge/barclamp-deployer/pull/57
https://bugzilla.novell.com/show_bug.cgi?id=774967
http://xforce.iss.net/xforce/xfdb/78041
http://www.securityfocus.com/bid/55240
http://www.openwall.com/lists/oss-security/2012/08/27/7
http://www.openwall.com/lists/oss-security/2012/08/27/5
http://secunia.com/advisories/50442
http://osvdb.org/84955

Copyright 2024, cxsecurity.com

 

Back to Top