CVE-2012-5605

Impact:
Moderate
Public Date:
2012-12-04
Bugzilla:
882138: CVE-2012-5605 CloudForms grinder: /var/lib/pulp/cache/grinder directory is world-writeable

The MITRE CVE dictionary describes this issue as:

Grinder in Red Hat CloudForms before 1.1 uses world-writable permissions for /var/lib/pulp/cache/grinder/, which allows local users to modify grinder cache files.

Find out more about CVE-2012-5605 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

Red Hat Update Infrastructure 2.1.3 is now in Production 2 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Update Infrastructure Life Cycle: https://access.redhat.com/support/policy/updates/rhui.

CVSS v2 metrics

Base Score 4.6
Base Metrics AV:L/AC:L/Au:N/C:P/I:P/A:P
Access Vector Local
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat CloudForms System Engine 1 (grinder) RHSA-2012:1543 2012-12-04
Red Hat CloudForms Tools 1 RHSA-2012:1543 2012-12-04
Red Hat CloudForms Tools 1 RHSA-2012:1543 2012-12-04

Acknowledgements

This issue was discovered by James Labocki of Red Hat.

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.