CVE-2012-5477: Low severity theforeman foreman vulnerability
Published May 8, 2014
·Updated
The smart proxy in Foreman before 1.1 uses a umask set to 0, which allows local users to modify files created by the daemon via unspecified vectors.
Affected Software
1 affected component
theforeman foreman<=1.0
Event History
May 8, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2012-5477?
The severity of CVE-2012-5477 is classified as medium due to the potential for local users to modify critical files.
2
How do I fix CVE-2012-5477?
To fix CVE-2012-5477, update Foreman to version 1.1 or later to ensure the umask is set properly.
3
Who is affected by CVE-2012-5477?
CVE-2012-5477 affects users of Foreman versions before 1.1 that allow local access.
4
What type of vulnerability is CVE-2012-5477?
CVE-2012-5477 is a local privilege escalation vulnerability due to improper file permissions.
5
Can CVE-2012-5477 be exploited remotely?
CVE-2012-5477 cannot be exploited remotely as it requires local access to the affected systems.