First published: Tue Sep 11 2012(Updated: )
GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/glusterfs | 5.5-3 9.2-1 10.3-5 11.0-3 | |
Gluster GlusterFS | =3.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4417 is classified as a medium severity vulnerability due to the potential for local users to perform unauthorized file operations.
To fix CVE-2012-4417, update GlusterFS to a version that is not vulnerable, such as versions 5.5-3, 9.2-1, 10.3-5, or 11.0-3.
CVE-2012-4417 affects GlusterFS version 3.3.0, particularly as used in the Red Hat Storage server 2.0.
CVE-2012-4417 allows a local user to perform a symlink attack, leading to overwriting arbitrary files.
CVE-2012-4417 was reported in 2012 and affects certain versions of GlusterFS.