{ "CVE_data_meta" : { "ASSIGNER" : "cve@mitre.org", "ID" : "CVE-2012-3537", "STATE" : "PUBLIC" }, "affects" : { "vendor" : { "vendor_data" : [ { "product" : { "product_data" : [ { "product_name" : "n/a", "version" : { "version_data" : [ { "version_value" : "n/a" } ] } } ] }, "vendor_name" : "n/a" } ] } }, "data_format" : "MITRE", "data_type" : "CVE", "data_version" : "4.0", "description" : { "description_data" : [ { "lang" : "eng", "value" : "The Crowbar Ohai plugin (chef/cookbooks/ohai/files/default/plugins/crowbar.rb) in the Deployer Barclamp in Crowbar, possibly 1.4 and earlier, allows local users to execute arbitrary shell commands via vectors related to \"insecure handling of tmp files\" and predictable file names." } ] }, "problemtype" : { "problemtype_data" : [ { "description" : [ { "lang" : "eng", "value" : "n/a" } ] } ] }, "references" : { "reference_data" : [ { "name" : "[oss-security] 20120827 CVE request: crowbar ohai plugin: local privilege (root) escalation due to insecure tmp file handling", "refsource" : "MLIST", "url" : "http://www.openwall.com/lists/oss-security/2012/08/27/5" }, { "name" : "[oss-security] 20120827 Re: CVE request: crowbar ohai plugin: local privilege (root) escalation due to insecure tmp file handling", "refsource" : "MLIST", "url" : "http://www.openwall.com/lists/oss-security/2012/08/27/7" }, { "name" : "https://bugzilla.novell.com/show_bug.cgi?id=774967", "refsource" : "MISC", "url" : "https://bugzilla.novell.com/show_bug.cgi?id=774967" }, { "name" : "https://github.com/SUSE-Cloud/barclamp-deployer/commit/5ea8d4ddaa4cb1ce834d36889f0fe7ac0d617bc8", "refsource" : "MISC", "url" : "https://github.com/SUSE-Cloud/barclamp-deployer/commit/5ea8d4ddaa4cb1ce834d36889f0fe7ac0d617bc8" }, { "name" : "https://github.com/SUSE-Cloud/barclamp-deployer/commit/b6454268a067fc77ff5de82057b5b53b3cc38b87", "refsource" : "MISC", "url" : "https://github.com/SUSE-Cloud/barclamp-deployer/commit/b6454268a067fc77ff5de82057b5b53b3cc38b87" }, { "name" : "https://github.com/dellcloudedge/barclamp-deployer/pull/57", "refsource" : "CONFIRM", "url" : "https://github.com/dellcloudedge/barclamp-deployer/pull/57" }, { "name" : "55240", "refsource" : "BID", "url" : "http://www.securityfocus.com/bid/55240" }, { "name" : "84955", "refsource" : "OSVDB", "url" : "http://osvdb.org/84955" }, { "name" : "50442", "refsource" : "SECUNIA", "url" : "http://secunia.com/advisories/50442" }, { "name" : "crowbar-privilege-escalation(78041)", "refsource" : "XF", "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/78041" } ] } }