CVE-2012-4884: Code Injection
Published Nov 11, 2012
·Updated
Argument injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to create arbitrary files via unspecified vectors related to the GnuPG client.
Affected Software
70 affected components
bestpractical RT=3.8.0
bestpractical RT=3.8.0-preflight1
bestpractical RT=3.8.0-rc1
bestpractical RT=3.8.0-rc2
bestpractical RT=3.8.0-rc3
bestpractical RT=3.8.1
bestpractical RT=3.8.1-preflight0
bestpractical RT=3.8.1-rc1
bestpractical RT=3.8.1-rc2
bestpractical RT=3.8.1-rc3
bestpractical RT=3.8.1-rc4
bestpractical RT=3.8.1-rc5
bestpractical RT=3.8.2
bestpractical RT=3.8.2-rc1
bestpractical RT=3.8.2-rc2
bestpractical RT=3.8.3
bestpractical RT=3.8.3-rc1
bestpractical RT=3.8.3-rc2
bestpractical RT=3.8.4
bestpractical RT=3.8.4-rc1
bestpractical RT=3.8.5
bestpractical RT=3.8.6
bestpractical RT=3.8.6-rc1
bestpractical RT=3.8.7
bestpractical RT=3.8.7-rc1
bestpractical RT=3.8.8
bestpractical RT=3.8.8-rc2
bestpractical RT=3.8.8-rc3
bestpractical RT=3.8.8-rc4
bestpractical RT=3.8.9
bestpractical RT=3.8.9-rc1
bestpractical RT=3.8.9-rc2
bestpractical RT=3.8.9-rc3
bestpractical RT=3.8.10
bestpractical RT=3.8.10-rc1
bestpractical RT=3.8.11
bestpractical RT=3.8.11-rc1
bestpractical RT=3.8.11-rc2
bestpractical RT=3.8.12
bestpractical RT=3.8.13
bestpractical RT=3.8.13-rc1
bestpractical RT=3.8.13-rc2
bestpractical RT=3.8.14
bestpractical RT=3.8.14-rc1
bestpractical RT=4.0.0
bestpractical RT=4.0.0-rc1
bestpractical RT=4.0.0-rc2
bestpractical RT=4.0.0-rc3
bestpractical RT=4.0.0-rc4
bestpractical RT=4.0.0-rc5
bestpractical RT=4.0.0-rc6
bestpractical RT=4.0.0-rc7
bestpractical RT=4.0.0-rc8
bestpractical RT=4.0.1
bestpractical RT=4.0.1-rc1
bestpractical RT=4.0.1-rc2
bestpractical RT=4.0.2
bestpractical RT=4.0.2-rc1
bestpractical RT=4.0.2-rc2
bestpractical RT=4.0.3
bestpractical RT=4.0.3-rc1
bestpractical RT=4.0.3-rc2
bestpractical RT=4.0.4
bestpractical RT=4.0.5
bestpractical RT=4.0.5-rc1
bestpractical RT=4.0.6
bestpractical RT=4.0.7
bestpractical RT=4.0.7-rc1
bestpractical RT=4.0.8-rc1
bestpractical RT=4.0.8-rc2
Event History
Nov 11, 2012
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4884?
The severity of CVE-2012-4884 is classified as high due to the potential for remote attackers to create arbitrary files.
2
How do I fix CVE-2012-4884?
To fix CVE-2012-4884, upgrade to Request Tracker version 3.8.15 or 4.0.8 or later.
3
What versions are affected by CVE-2012-4884?
CVE-2012-4884 affects Request Tracker versions 3.8.0 through 3.8.14 and 4.0.0 through 4.0.7.
4
Can CVE-2012-4884 be exploited remotely?
Yes, CVE-2012-4884 can be exploited by remote attackers without requiring authentication.
5
What type of vulnerability is CVE-2012-4884?
CVE-2012-4884 is an argument injection vulnerability related to the GnuPG client.