bugs.debian.org
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=665923 CVE-2012-1586
mount.cifs - 'chdir()' Arbitrary Root File Identification
Record summary
CVE-2012-1586 has a selected CVSS score of 2.1; EIP currently links 1 catalogued exploit.
Description
mount.cifs in cifs-utils 2.6 allows local users to determine the existence of arbitrary files or directories via the file path in the second argument, which reveals their existence in an error message.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBmount.cifs - 'chdir()' Arbitrary Root File IdentificationExploitDB exploitby Sha0Not analyzed1 file
References
6SUSE-SU-2012:0575Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00024.html [oss-security] 20120327 CVE id request: cifs-utilsmailing list
http://www.openwall.com/lists/oss-security/2012/03/27/1 [oss-security] 20120327 Re: CVE id request: cifs-utilsmailing list
http://www.openwall.com/lists/oss-security/2012/03/27/6 bugzilla.samba.orgConfirmation
https://bugzilla.samba.org/show_bug.cgi?id=8821 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2012-1586