CVE-2010-4512: High severity Michael Dehaan Cobbler vulnerability
Published Dec 9, 2010
·Updated
Cobbler before 2.0.4 uses an incorrect umask value, which allows local users to have an unspecified impact by leveraging world writable permissions for files and directories.
Affected Software
80 affected components
Michael Dehaan Cobbler<=2.0.3.1-2
Michael Dehaan Cobbler=0.1.1.7
Michael Dehaan Cobbler=0.2.1
Michael Dehaan Cobbler=0.2.2
Michael Dehaan Cobbler=0.2.3
Michael Dehaan Cobbler=0.2.5
Michael Dehaan Cobbler=0.2.7
Michael Dehaan Cobbler=0.2.8
Michael Dehaan Cobbler=0.2.9
Michael Dehaan Cobbler=0.3.0
Michael Dehaan Cobbler=0.3.1
Michael Dehaan Cobbler=0.3.3
Michael Dehaan Cobbler=0.3.4
Michael Dehaan Cobbler=0.3.5
Michael Dehaan Cobbler=0.3.6
Michael Dehaan Cobbler=0.3.7
Michael Dehaan Cobbler=0.3.9
Michael Dehaan Cobbler=0.4.0
Michael Dehaan Cobbler=0.4.2
Michael Dehaan Cobbler=0.4.3
Michael Dehaan Cobbler=0.4.5
Michael Dehaan Cobbler=0.4.6
Michael Dehaan Cobbler=0.4.7
Michael Dehaan Cobbler=0.4.8
Michael Dehaan Cobbler=0.5.0
Michael Dehaan Cobbler=0.6.0
Michael Dehaan Cobbler=0.6.1
Michael Dehaan Cobbler=0.6.3
Michael Dehaan Cobbler=0.6.4
Michael Dehaan Cobbler=0.6.5
Michael Dehaan Cobbler=0.8.1
Michael Dehaan Cobbler=0.8.3
Michael Dehaan Cobbler=1.0.0
Michael Dehaan Cobbler=1.0.2
Michael Dehaan Cobbler=1.0.2-1
Michael Dehaan Cobbler=1.0.3-1
Michael Dehaan Cobbler=1.2.0
Michael Dehaan Cobbler=1.2.2
Michael Dehaan Cobbler=1.2.3
Michael Dehaan Cobbler=1.2.5
Michael Dehaan Cobbler=1.2.6
Michael Dehaan Cobbler=1.2.7
Michael Dehaan Cobbler=1.2.8
Michael Dehaan Cobbler=1.2.8-1
Michael Dehaan Cobbler=1.2.9
Michael Dehaan Cobbler=1.2.9-1
Michael Dehaan Cobbler=1.3.1
Michael Dehaan Cobbler=1.3.1-1
Michael Dehaan Cobbler=1.3.3
Michael Dehaan Cobbler=1.3.3-1
Michael Dehaan Cobbler=1.3.4
Michael Dehaan Cobbler=1.3.4-1
Michael Dehaan Cobbler=1.4.0
Michael Dehaan Cobbler=1.4.0-2
Michael Dehaan Cobbler=1.4.1
Michael Dehaan Cobbler=1.4.1-1
Michael Dehaan Cobbler=1.4.2
Michael Dehaan Cobbler=1.4.2-1
Michael Dehaan Cobbler=1.4.3
Michael Dehaan Cobbler=1.4.3-4
Michael Dehaan Cobbler=1.6.1
Michael Dehaan Cobbler=1.6.1-1
Michael Dehaan Cobbler=1.6.2
Michael Dehaan Cobbler=1.6.2-1
Michael Dehaan Cobbler=1.6.3
Michael Dehaan Cobbler=1.6.3-1
Michael Dehaan Cobbler=1.6.4
Michael Dehaan Cobbler=1.6.4-1
Michael Dehaan Cobbler=1.6.5
Michael Dehaan Cobbler=1.6.5-1
Michael Dehaan Cobbler=1.6.6
Michael Dehaan Cobbler=1.6.6-1
Michael Dehaan Cobbler=1.6.8
Michael Dehaan Cobbler=1.6.8-1
Michael Dehaan Cobbler=2.0.0
Michael Dehaan Cobbler=2.0.0-1
Michael Dehaan Cobbler=2.0.1
Michael Dehaan Cobbler=2.0.1-1
Michael Dehaan Cobbler=2.0.3
Michael Dehaan Cobbler=2.0.3.1
Remediation
Event History
Dec 9, 2010
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-4512?
CVE-2010-4512 has a medium severity rating as it allows local users to exploit unwanted permissions.
2
How do I fix CVE-2010-4512?
To fix CVE-2010-4512, update Cobbler to version 2.0.4 or later, which addresses the incorrect umask configuration.
3
Which versions of Cobbler are affected by CVE-2010-4512?
CVE-2010-4512 affects Cobbler versions prior to 2.0.4, including 1.0.2, 1.6.1, and several others.
4
What impact does CVE-2010-4512 have on file permissions?
CVE-2010-4512 allows unintended world writable permissions, potentially exposing sensitive files to unauthorized access by local users.
5
Is CVE-2010-4512 a remote access vulnerability?
No, CVE-2010-4512 is a local vulnerability that requires local user access to exploit the issue.