Vulnerability Name:

CVE-2012-0871 (CCN-73590)

Assigned:2012-02-29
Published:2012-02-29
Updated:2022-01-28
Summary:The session_link_x11_socket function in login/logind-session.c in systemd-logind in systemd, possibly 37 and earlier, allows local users to create or overwrite arbitrary files via a symlink attack on the X11 user directory in /run/user/.
CVSS v3 Severity:5.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:6.3 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:C/A:C)
5.5 Medium (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:C/A:C/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Complete
Availibility (A): Complete
3.3 Low (CCN CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P)
2.9 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-59
Vulnerability Consequences:File Manipulation
References:Source: CONFIRM
Type: UNKNOWN
http://cgit.freedesktop.org/systemd/systemd/commit/?id=fc3c1c6e091ea16ad5600b145201ec535bbb5d7c

Source: MITRE
Type: CNA
CVE-2012-0871

Source: SUSE
Type: UNKNOWN
SUSE-SA:2012:001

Source: CCN
Type: SA48208
systemd X11 Session File Creation Weakness

Source: CCN
Type: freedesktop Web site
systemd System and Service Manager

Source: OSVDB
Type: UNKNOWN
79768

Source: CCN
Type: OSVDB ID: 79768
systemd systemd-logind Component X11 Session File Creation Symlink Local Privilege Escalation

Source: CCN
Type: BID-52230
systemd 'systemd-logind' Insecure File Creation Vulnerability

Source: CCN
Type: VUL-0 Bug 747154
VUL-0: systemd messes with /run/user/user files during login

Source: CONFIRM
Type: UNKNOWN
https://bugzilla.novell.com/show_bug.cgi?id=747154

Source: CONFIRM
Type: UNKNOWN
https://bugzilla.redhat.com/show_bug.cgi?id=795853

Source: XF
Type: UNKNOWN
systemd-systemdlogind-symlink(73590)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:systemd_project:systemd:31:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:30:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:29:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:28:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:14:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:13:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:12:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:11:*:*:*:*:*:*:*
  • OR cpe:/o:opensuse:opensuse:12.1:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:*:*:*:*:*:*:*:* (Version <= 037)
  • OR cpe:/a:systemd_project:systemd:36:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:23:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:22:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:21:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:20:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:19:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:6:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:5:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:4:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:3:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:34:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:32:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:27:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:25:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:18:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:16:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:9:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:7:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:2:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:35:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:33:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:26:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:24:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:17:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:15:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:10:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:8:*:*:*:*:*:*:*
  • OR cpe:/a:systemd_project:systemd:1:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:systemd_project:systemd:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20120871
    V
    CVE-2012-0871
    2013-08-14
    BACK
    systemd_project systemd 31
    systemd_project systemd 30
    systemd_project systemd 29
    systemd_project systemd 28
    systemd_project systemd 14
    systemd_project systemd 13
    systemd_project systemd 12
    systemd_project systemd 11
    opensuse opensuse 12.1
    systemd_project systemd *
    systemd_project systemd 36
    systemd_project systemd 23
    systemd_project systemd 22
    systemd_project systemd 21
    systemd_project systemd 20
    systemd_project systemd 19
    systemd_project systemd 6
    systemd_project systemd 5
    systemd_project systemd 4
    systemd_project systemd 3
    systemd_project systemd 34
    systemd_project systemd 32
    systemd_project systemd 27
    systemd_project systemd 25
    systemd_project systemd 18
    systemd_project systemd 16
    systemd_project systemd 9
    systemd_project systemd 7
    systemd_project systemd 2
    systemd_project systemd 35
    systemd_project systemd 33
    systemd_project systemd 26
    systemd_project systemd 24
    systemd_project systemd 17
    systemd_project systemd 15
    systemd_project systemd 10
    systemd_project systemd 8
    systemd_project systemd 1
    systemd_project systemd *