The Crowbar Ohai plugin (chef/cookbooks/ohai/files/default/plugins/crowbar.rb) in the Deployer Barclamp in Crowbar, possibly 1.4 and earlier, allows local users to execute arbitrary shell commands via vectors related to "insecure handling of tmp files" and predictable file names.
References
Configurations
History
21 Nov 2024, 01:41
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/84955 - | |
References | () http://secunia.com/advisories/50442 - Vendor Advisory | |
References | () http://www.openwall.com/lists/oss-security/2012/08/27/5 - | |
References | () http://www.openwall.com/lists/oss-security/2012/08/27/7 - | |
References | () http://www.securityfocus.com/bid/55240 - | |
References | () https://bugzilla.novell.com/show_bug.cgi?id=774967 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/78041 - | |
References | () https://github.com/SUSE-Cloud/barclamp-deployer/commit/5ea8d4ddaa4cb1ce834d36889f0fe7ac0d617bc8 - Exploit, Patch | |
References | () https://github.com/SUSE-Cloud/barclamp-deployer/commit/b6454268a067fc77ff5de82057b5b53b3cc38b87 - Exploit, Patch | |
References | () https://github.com/dellcloudedge/barclamp-deployer/pull/57 - |
Information
Published : 2012-09-05 23:55
Updated : 2024-11-21 01:41
NVD link : CVE-2012-3537
Mitre link : CVE-2012-3537
CVE.ORG link : CVE-2012-3537
JSON object : View
Products Affected
dell
- crowbar
CWE
CWE-264
Permissions, Privileges, and Access Controls