Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 444098 (CVE-2012-4417)

Summary: <sys-cluster/glusterfs-3.3.0: Symlink vulnerabilities (CVE-2012-4417)
Product: Gentoo Security Reporter: GLSAMaker/CVETool Bot <glsamaker>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: alexxy, cluster
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: B3 [noglsa cve]
Package list:
Runtime testing required: ---
Bug Depends on: 541540    
Bug Blocks:    

Description GLSAMaker/CVETool Bot gentoo-dev 2012-11-20 21:22:12 UTC
CVE-2012-4417 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4417):
  GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users
  to overwrite arbitrary files via a symlink attack on temporary files with
  predictable names.
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2017-02-10 22:49:32 UTC
GLSA Vote: No

All done, repository is clean.