2.1 CVE-2012-5509

Exploit Ransomware Risk
 

aeolus-configserver-setup in the Aeolas Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for a temporary file in /tmp, which allows local users to read credentials by reading this file.
https://nvd.nist.gov/vuln/detail/CVE-2012-5509

Categories

CWE-264

References


 

CPE

cpe start end
Configuration 1
cpe:2.3:a:redhat:cloudforms_cloud_engine:*:*:*:*:*:*:*:* <= 1.1
cpe:2.3:a:redhat:cloudforms_cloud_engine:1.0:*:*:*:*:*:*:*


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

Other (github, ...)

Url
https://bugzilla.redhat.com/show_bug.cgi?id=875294


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry


MITRE