← Back

CVE-2012-2291

nvd nist
Published: Jan 21, 2013Modified: Apr 29, 2026

JSON object

Loading...
7.2
Vector
AV:L/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 3.9 / Impact: 10.0
Source: NVD

Description

EMC Avamar Client 4.x, 5.x, and 6.x on HP-UX and Mac OS X, and the EMC Avamar plugin 4.x, 5.x, and 6.x for Oracle, uses world-writable permissions for cache directories, which allows local users to gain privileges via an unspecified symlink attack.

Affected (12)

2 products
Avamar
Avamar Plugin
Configuration A
8 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Emc
Version 4.0
Version 4.1
Version 5.0.0-407
Version 5.0.4-26
Version 5.0
Version 5.0 sp1
Version 5.0 sp2
Version 6.0
Running on/withPlatform Versions
Apple
Mac Os X
All versions
Hp
Hp Ux
All versions
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Emc
Version 4.0
Version 5.0
Version 6.0
Version 6.1

Related CWEs

References (2)

Timeline

No history available yet.