Vulnerability Description
The GridFTP in Globus Toolkit (GT) before 5.2.2, when certain autoconf macros are defined, does not properly check the return value from the getpwnam_r function, which might allow remote attackers to gain privileges by logging in with a user that does not exist, which causes GridFTP to run as the last user in the password file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Globus | Globus Toolkit | <= 5.2.1 |
Related Weaknesses (CWE)
References
- http://jira.globus.org/browse/GT-195
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081787.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081791.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081797.html
- http://www.debian.org/security/2012/dsa-2523
- http://jira.globus.org/browse/GT-195
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081787.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081791.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081797.html
- http://www.debian.org/security/2012/dsa-2523
FAQ
What is CVE-2012-3292?
CVE-2012-3292 is a vulnerability with a CVSS score of 7.6 (HIGH). The GridFTP in Globus Toolkit (GT) before 5.2.2, when certain autoconf macros are defined, does not properly check the return value from the getpwnam_r function, which might allow remote attackers to ...
How severe is CVE-2012-3292?
CVE-2012-3292 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-3292?
Check the references section above for vendor advisories and patch information. Affected products include: Globus Globus Toolkit.