First published: Fri Nov 30 2012(Updated: )
Grinder in Red Hat CloudForms before 1.1 uses world-writable permissions for /var/lib/pulp/cache/grinder/, which allows local users to modify grinder cache files.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat CloudForms | <=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-5605 is classified as a high severity vulnerability due to its potential to allow unauthorized local user access to modify files.
To fix CVE-2012-5605, you should change the permissions of the /var/lib/pulp/cache/grinder directory to restrict write access.
CVE-2012-5605 was reported by James Labocki of Red Hat.
CVE-2012-5605 affects Red Hat CloudForms versions prior to 1.1.
The directory associated with CVE-2012-5605 is /var/lib/pulp/cache/grinder.