CVE-2012-2291: High severity EMC Avamar vulnerability
Published Jan 21, 2013
·Updated
EMC Avamar Client 4.x, 5.x, and 6.x on HP-UX and Mac OS X, and the EMC Avamar plugin 4.x, 5.x, and 6.x for Oracle, uses world-writable permissions for cache directories, which allows local users to gain privileges via an unspecified symlink attack.
Affected Software
14 affected components
EMC Avamar=4.0
EMC Avamar=4.1
EMC Avamar=5.0
EMC Avamar=5.0-sp1
EMC Avamar=5.0-sp2
EMC Avamar=5.0.0-407
EMC Avamar=5.0.4-26
EMC Avamar=6.0
Apple iOS and macOS
HP HP-UX
EMC Avamar plugin=4.0
EMC Avamar plugin=5.0
EMC Avamar plugin=6.0
EMC Avamar plugin=6.1
Event History
Jan 21, 2013
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2291?
CVE-2012-2291 is considered a moderate severity vulnerability due to its potential to allow local users to gain privileges.
2
How do I fix CVE-2012-2291?
Fix CVE-2012-2291 by changing the permissions of the cache directories to remove world-writable rights.
3
Which EMC Avamar versions are affected by CVE-2012-2291?
CVE-2012-2291 affects EMC Avamar versions 4.x, 5.x, and 6.x.
4
Can local users exploit CVE-2012-2291?
Yes, local users can exploit CVE-2012-2291 through an unspecified symlink attack.
5
Is there a specific operating system affected by CVE-2012-2291?
CVE-2012-2291 specifically affects EMC Avamar on HP-UX and macOS.