CVE-2012-3537

Dell Crowbar < 1.4 - Local Arbitrary Command Execution via Insecure Temporary File Handling

Title source: llm
STIX 2.1

Description

The Crowbar Ohai plugin (chef/cookbooks/ohai/files/default/plugins/crowbar.rb) in the Deployer Barclamp in Crowbar, possibly 1.4 and earlier, allows local users to execute arbitrary shell commands via vectors related to "insecure handling of tmp files" and predictable file names.

References (10)

Core 10
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/78041
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/08/27/7
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/55240
Issue Tracking x_refsource_misc
https://bugzilla.novell.com/show_bug.cgi?id=774967
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/50442
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/84955
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/08/27/5

Scores

EPSS 0.0024
EPSS Percentile 46.9%

Details

CWE
CWE-264
Status published
Products (1)
dell/crowbar < 1.4
Published Sep 05, 2012
Tracked Since Feb 18, 2026