First published: Thu May 08 2014(Updated: )
The smart proxy in Foreman before 1.1 uses a umask set to 0, which allows local users to modify files created by the daemon via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
The Foreman | <=1.0 | |
<=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2012-5477 is classified as medium due to the potential for local users to modify critical files.
To fix CVE-2012-5477, update Foreman to version 1.1 or later to ensure the umask is set properly.
CVE-2012-5477 affects users of Foreman versions before 1.1 that allow local access.
CVE-2012-5477 is a local privilege escalation vulnerability due to improper file permissions.
CVE-2012-5477 cannot be exploited remotely as it requires local access to the affected systems.