← Back

CVE-2012-0787

nvd nist
Published: Nov 23, 2013Modified: Apr 29, 2026

JSON object

Loading...
3.7
Vector
AV:L/AC:H/Au:N/C:P/I:P/A:P
Exploitability: 1.9 / Impact: 6.4
Source: NVD

Description

The clone_file function in transfer.c in Augeas before 1.0.0, when copy_if_rename_fails is set and EXDEV or EBUSY is returned by the rename function, allows local users to overwrite arbitrary files and obtain sensitive information via a bind mount on the (1) .augsave or (2) destination file when using the backup save option, or (3) .augnew file when using the newfile save option.

Affected (38)

1 product
Enterprise Linux
1 product
Augeas
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 6.0
Configuration B
37 vulnerable
Vulnerable SoftwareAffected Versions
Augeas
Up to 0.10.0
Version 0.0.1
Version 0.0.2
Version 0.0.3
Version 0.0.4
Version 0.0.5
Version 0.0.6
Version 0.0.7
Version 0.0.8
Version 0.1.0
Version 0.1.1
Version 0.2.0
Version 0.2.1
Version 0.2.2
Version 0.3.0
Version 0.3.1
Version 0.3.2
Version 0.3.3
Version 0.3.4
Version 0.3.5
Version 0.3.6
Version 0.4.0
Version 0.4.1
Version 0.4.2
Version 0.5.0
Version 0.5.1
Version 0.5.2
Version 0.5.3
Version 0.6.0
Version 0.7.0
Version 0.7.1
Version 0.7.2
Version 0.7.3
Version 0.7.4
Version 0.8.0
Version 0.8.1
Version 0.9.0

References (10)

Source: secalert@redhat.com
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Exploit
Source: secalert@redhat.com
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch

Timeline

No history available yet.