CVE-2012-2682: Input Validation
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, allows attackers with certain database privileges to cause a denial of service (inaccessible page) via a non-ASCII character in the name of a link.
Other sources
It was found that when Cumin was asked to display a link name that contained non-ASCII characters, it would exit with an error and not display the content of the page with the link in it. Due to incomplete support for Unicode, if an administrator were to add data to the database (via Cumin or Wallaby, among others) that contained non-ASCII characters, subsequent requests to load data containing these characters would result in unexpected termination of the Cumin request, and the requested page would not be displayed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2682?
CVE-2012-2682 is classified as a high severity vulnerability that can cause denial of service in the affected systems.
How do I fix CVE-2012-2682?
To mitigate CVE-2012-2682, you should apply the latest security patches provided by Red Hat for the Red Hat Enterprise MRG 2.5.
What software is affected by CVE-2012-2682?
CVE-2012-2682 affects Red Hat Enterprise MRG version 2.5.
What type of attack is CVE-2012-2682 associated with?
CVE-2012-2682 allows attackers with specific database privileges to launch denial of service attacks by using non-ASCII characters in link names.
Can CVE-2012-2682 be exploited remotely?
Yes, CVE-2012-2682 can potentially be exploited remotely by users with certain database privileges.