Executive Summary

Informations
Name CVE-2012-3417 First vendor Publication 2012-08-13
Vendor Cve Last vendor Modification 2024-11-21

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:H/Au:N/C:P/I:P/A:N)
Cvss Base Score 4 Attack Range Network
Cvss Impact Score 4.9 Attack Complexity High
Cvss Expoit Score 4.9 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

The good_client function in rquotad (rquota_svc.c) in Linux DiskQuota (aka quota) before 3.17 invokes the hosts_ctl function the first time without a host name, which might allow remote attackers to bypass TCP Wrappers rules in hosts.deny.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3417

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-264 Permissions, Privileges, and Access Controls

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:21025
 
Oval ID: oval:org.mitre.oval:def:21025
Title: RHSA-2013:0120: quota security and bug fix update (Low)
Description: The good_client function in rquotad (rquota_svc.c) in Linux DiskQuota (aka quota) before 3.17 invokes the hosts_ctl function the first time without a host name, which might allow remote attackers to bypass TCP Wrappers rules in hosts.deny.
Family: unix Class: patch
Reference(s): RHSA-2013:0120-00
CESA-2013:0120
CVE-2012-3417
Version: 4
Platform(s): Red Hat Enterprise Linux 5
CentOS Linux 5
Product(s): quota
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:23266
 
Oval ID: oval:org.mitre.oval:def:23266
Title: ELSA-2013:0120: quota security and bug fix update (Low)
Description: The good_client function in rquotad (rquota_svc.c) in Linux DiskQuota (aka quota) before 3.17 invokes the hosts_ctl function the first time without a host name, which might allow remote attackers to bypass TCP Wrappers rules in hosts.deny.
Family: unix Class: patch
Reference(s): ELSA-2013:0120-00
CVE-2012-3417
Version: 6
Platform(s): Oracle Linux 5
Product(s): quota
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:27560
 
Oval ID: oval:org.mitre.oval:def:27560
Title: DEPRECATED: ELSA-2013-0120 -- quota security and bug fix update (low)
Description: [1:3.13-8.0.1] - Add ocfs2 support (Orabug: 14208111) [1:3.13-8] - Fix CVE-2012-3417 (incorrect use of tcp_wrappers) (Resolves: #841448) [1:3.13-7] - Fix parsing numeric arguments of setquota (Resolves: #831520) [1:3.13-6] - Do not use real domains in warnquota example (Resolves: #680429) - Use /proc/mounts for mountpoint scanning (Resolves: #689822) - Use rq_bsize to convert quotas transferred by RPC (bug #667360) - Make RPC block factor dynamic (bug #667360)
Family: unix Class: patch
Reference(s): ELSA-2013-0120
CVE-2012-3417
Version: 4
Platform(s): Oracle Linux 5
Product(s): quota
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 24

Nessus® Vulnerability Scanner

Date Description
2014-06-13 Name : The remote openSUSE host is missing a security update.
File : openSUSE-2012-529.nasl - Type : ACT_GATHER_INFO
2013-07-12 Name : The remote Oracle Linux host is missing a security update.
File : oraclelinux_ELSA-2013-0120.nasl - Type : ACT_GATHER_INFO
2013-01-25 Name : The remote SuSE 11 host is missing one or more security updates.
File : suse_11_quota-120823.nasl - Type : ACT_GATHER_INFO
2013-01-25 Name : The remote SuSE 11 host is missing one or more security updates.
File : suse_11_quota-120829.nasl - Type : ACT_GATHER_INFO
2013-01-17 Name : The remote CentOS host is missing a security update.
File : centos_RHSA-2013-0120.nasl - Type : ACT_GATHER_INFO
2013-01-17 Name : The remote Scientific Linux host is missing one or more security updates.
File : sl_20130108_quota_on_SL5_x.nasl - Type : ACT_GATHER_INFO
2013-01-08 Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2013-0120.nasl - Type : ACT_GATHER_INFO
2012-09-04 Name : The remote SuSE 10 host is missing a security-related patch.
File : suse_quota-8255.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://linuxquota.git.sourceforge.net/git/gitweb.cgi?p=linuxquota/linuxquota%...
http://rhn.redhat.com/errata/RHSA-2013-0120.html
http://sourceforge.net/tracker/?func=detail&aid=2743481&group_id=1813...
http://www.openwall.com/lists/oss-security/2012/07/19/2
http://www.openwall.com/lists/oss-security/2012/07/19/5
https://bugzilla.redhat.com/show_bug.cgi?id=566717
https://hermes.opensuse.org/messages/15509723
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
Date Informations
2024-11-28 23:00:40
  • Multiple Updates
2024-11-28 12:30:42
  • Multiple Updates
2023-02-13 09:28:40
  • Multiple Updates
2021-05-04 12:21:05
  • Multiple Updates
2021-04-22 01:25:12
  • Multiple Updates
2020-05-23 01:49:13
  • Multiple Updates
2020-05-23 00:34:10
  • Multiple Updates
2016-12-08 09:23:25
  • Multiple Updates
2014-06-14 13:33:10
  • Multiple Updates
2014-02-17 11:11:38
  • Multiple Updates
2013-05-10 22:42:27
  • Multiple Updates
2013-01-15 13:21:15
  • Multiple Updates