Description
The clone_file function in transfer.c in Augeas before 1.0.0, when copy_if_rename_fails is set and EXDEV or EBUSY is returned by the rename function, allows local users to overwrite arbitrary files and obtain sensitive information via a bind mount on the (1) .augsave or (2) destination file when using the backup save option, or (3) .augnew file when using the newfile save option.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-28-1 | augeas security update |
EUVD |
EUVD-2012-0818 | The clone_file function in transfer.c in Augeas before 1.0.0, when copy_if_rename_fails is set and EXDEV or EBUSY is returned by the rename function, allows local users to overwrite arbitrary files and obtain sensitive information via a bind mount on the (1) .augsave or (2) destination file when using the backup save option, or (3) .augnew file when using the newfile save option. |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T18:38:14.202Z
Reserved: 2012-01-19T00:00:00.000Z
Link: CVE-2012-0787
No data.
Status : Deferred
Published: 2013-11-23T18:55:04.093
Modified: 2025-04-11T00:51:21.963
Link: CVE-2012-0787
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD