CVE-2012-3537
Summary
| CVE | CVE-2012-3537 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-09-05 23:55:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The Crowbar Ohai plugin (chef/cookbooks/ohai/files/default/plugins/crowbar.rb) in the Deployer Barclamp in Crowbar, possibly 1.4 and earlier, allows local users to execute arbitrary shell commands via vectors related to "insecure handling of tmp files" and predictable file names. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Dell 'Crowbar ohai' Plugin Local Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Access Denied | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.novell.com | |
| github.com/SUSE-Cloud/barclamp-deployer/commit/b6454268a067fc77ff5de8205... | af854a3a-2127-422b-91ae-364da2661108 | github.com | Exploit, Patch |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| github.com/SUSE-Cloud/barclamp-deployer/commit/5ea8d4ddaa4cb1ce834d36889... | af854a3a-2127-422b-91ae-364da2661108 | github.com | Exploit, Patch |
| Security Advisory SA50442 - Crowbar Ohai Plugin Insecure Temporary Files Security Issue - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| oss-security - CVE request: crowbar ohai plugin: local privilege (root) escalation due to insecure tmp file handling | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| github.com/dellcloudedge/barclamp-deployer/pull/57 | af854a3a-2127-422b-91ae-364da2661108 | github.com | |
| osvdb.org/84955 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| oss-security - Re: CVE request: crowbar ohai plugin: local privilege (root) escalation due to insecure tmp file handling | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.