CVE-2012-3537
Dell Crowbar < 1.4 - Local Arbitrary Command Execution via Insecure Temporary File Handling
Title source: llmDescription
The Crowbar Ohai plugin (chef/cookbooks/ohai/files/default/plugins/crowbar.rb) in the Deployer Barclamp in Crowbar, possibly 1.4 and earlier, allows local users to execute arbitrary shell commands via vectors related to "insecure handling of tmp files" and predictable file names.
References (10)
Core 10
Core References
Exploit, Patch x_refsource_misc
https://github.com/SUSE-Cloud/barclamp-deployer/commit/5ea8d4ddaa4cb1ce834d36889f0fe7ac0d617bc8
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/78041
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/08/27/7
Issue Tracking x_refsource_confirm
https://github.com/dellcloudedge/barclamp-deployer/pull/57
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/55240
Issue Tracking x_refsource_misc
https://bugzilla.novell.com/show_bug.cgi?id=774967
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/50442
Exploit, Patch x_refsource_misc
https://github.com/SUSE-Cloud/barclamp-deployer/commit/b6454268a067fc77ff5de82057b5b53b3cc38b87
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/84955
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/08/27/5
Scores
EPSS
0.0024
EPSS Percentile
46.9%
Details
CWE
CWE-264
Status
published
Products (1)
dell/crowbar
< 1.4
Published
Sep 05, 2012
Tracked Since
Feb 18, 2026