First published: Wed Dec 19 2012(Updated: )
IBM Advanced Settings Utility (ASU) through 3.62 and 3.70 through 9.21 and Bootable Media Creator (BoMC) through 2.30 and 3.00 through 9.21 on Linux allow local users to overwrite arbitrary files via a symlink attack on a (1) temporary file or (2) log file.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Advanced Settings Utility | =3.62 | |
IBM Advanced Settings Utility | =3.70 | |
IBM Advanced Settings Utility | =9.21 | |
IBM Bootable Media Creator | =2.30 | |
IBM Bootable Media Creator | =3.00 | |
IBM Bootable Media Creator | =9.21 | |
Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3329 has a medium severity rating due to its potential for local file overwrite vulnerabilities.
To fix CVE-2012-3329, update the IBM Advanced Settings Utility or Bootable Media Creator to the latest versions provided by IBM.
CVE-2012-3329 affects users of IBM Advanced Settings Utility versions 3.62, 3.70, and 9.21, as well as Bootable Media Creator versions 2.30, 3.00, and 9.21 on Linux.
A symlink attack in CVE-2012-3329 allows local users to create symbolic links to overwrite critical files, exploiting insufficient validation in temporary and log file handling.
Yes, CVE-2012-3329 is known to have potential exploit scenarios due to its vulnerabilities in local file handling practices.