CVE-2012-1586: Infoleak
Published Aug 27, 2012
·Updated
mount.cifs in cifs-utils 2.6 allows local users to determine the existence of arbitrary files or directories via the file path in the second argument, which reveals their existence in an error message.
Affected Software
1 affected component
Debian Cifs-utils=2.6
Event History
Aug 27, 2012
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-1586?
CVE-2012-1586 is classified as a medium severity vulnerability.
2
How does CVE-2012-1586 affect cifs-utils?
CVE-2012-1586 allows local users to determine the existence of arbitrary files or directories based on error messages produced by mount.cifs.
3
Which versions of cifs-utils are affected by CVE-2012-1586?
CVE-2012-1586 affects cifs-utils version 2.6.
4
How do I fix CVE-2012-1586?
To fix CVE-2012-1586, update cifs-utils to a version that is not vulnerable to this issue.
5
What is the impact of exploiting CVE-2012-1586?
Exploiting CVE-2012-1586 may lead to information disclosure about the file system.