CVE-2012-5605: Low severity red hat cloudforms vulnerability
Published Nov 30, 2012
·Updated
Grinder in Red Hat CloudForms before 1.1 uses world-writable permissions for /var/lib/pulp/cache/grinder/, which allows local users to modify grinder cache files.
Other sources
James Labocki of Red Hat reports:
The /var/lib/pulp/cache/grinder directory is world-writeable
— Red Hat
Affected Software
1 affected component
redhat Cloudforms<=1.0
Event History
Nov 30, 2012
Data Sourced
via Red Hat·08:58 AM
DescriptionSeverityAffected Software
Jan 4, 2013
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-5605?
CVE-2012-5605 is classified as a high severity vulnerability due to its potential to allow unauthorized local user access to modify files.
2
How do I fix CVE-2012-5605?
To fix CVE-2012-5605, you should change the permissions of the /var/lib/pulp/cache/grinder directory to restrict write access.
3
Who reported CVE-2012-5605?
CVE-2012-5605 was reported by James Labocki of Red Hat.
4
Which versions of Red Hat CloudForms are affected by CVE-2012-5605?
CVE-2012-5605 affects Red Hat CloudForms versions prior to 1.1.
5
What directory is associated with CVE-2012-5605?
The directory associated with CVE-2012-5605 is /var/lib/pulp/cache/grinder.