Vulnerability Name:

CVE-2012-3417 (CCN-77752)

Assigned:2009-04-22
Published:2009-04-22
Updated:2023-02-13
Summary:The good_client function in rquotad (rquota_svc.c) in Linux DiskQuota (aka quota) before 3.17 invokes the hosts_ctl function the first time without a host name, which might allow remote attackers to bypass TCP Wrappers rules in hosts.deny.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.0 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N)
3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.0 Medium (REDHAT CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N)
3.0 Low (REDHAT Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2012-3417

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: Linux DiskQuota GIT Repository
Fix hostname checking in rpc.rquotad

Source: CCN
Type: RHSA-2013-0120
Low: quota security and bug fix update

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: OSVDB ID: 84729
Linux DiskQuota rquota_svc.c good_client Function hosts.deny TCP Wrapper Rule Bypass

Source: CCN
Type: BID-55066
Linux DiskQuota 'hosts_ctl()' Security Bypass Vulnerability

Source: CCN
Type: Red Hat Bugzilla Bug 566717
CVE-2012-3417 quota: incorrect use of tcp_wrappers

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: XF
Type: UNKNOWN
linux-diskquota-sec-bypass(77752)

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:5::client:*:*:*:*:*
  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:5::server:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:jan_kara:linux_diskquota:3.16:*:*:*:*:*:*:*
  • OR cpe:/a:jan_kara:linux_diskquota:3.15:*:*:*:*:*:*:*
  • OR cpe:/a:jan_kara:linux_diskquota:3.14:*:*:*:*:*:*:*
  • OR cpe:/a:jan_kara:linux_diskquota:3.13:*:*:*:*:*:*:*
  • OR cpe:/a:jan_kara:linux_diskquota:3.12:*:*:*:*:*:*:*
  • OR cpe:/a:jan_kara:linux_diskquota:3.11:*:*:*:*:*:*:*
  • OR cpe:/a:jan_kara:linux_diskquota:3.10:*:*:*:*:*:*:*
  • OR cpe:/a:jan_kara:linux_diskquota:3.09:*:*:*:*:*:*:*
  • OR cpe:/a:jan_kara:linux_diskquota:3.08:*:*:*:*:*:*:*
  • OR cpe:/a:jan_kara:linux_diskquota:3.07:*:*:*:*:*:*:*
  • OR cpe:/a:jan_kara:linux_diskquota:3.06:*:*:*:*:*:*:*
  • OR cpe:/a:jan_kara:linux_diskquota:3.05:*:*:*:*:*:*:*
  • OR cpe:/a:jan_kara:linux_diskquota:3.04:*:*:*:*:*:*:*
  • OR cpe:/a:jan_kara:linux_diskquota:3.03:*:*:*:*:*:*:*
  • OR cpe:/a:jan_kara:linux_diskquota:3.02:*:*:*:*:*:*:*
  • OR cpe:/a:jan_kara:linux_diskquota:3.01:*:*:*:*:*:*:*
  • OR cpe:/a:jan_kara:linux_diskquota:3.01:pre9:*:*:*:*:*:*
  • OR cpe:/a:jan_kara:linux_diskquota:3.01:pre8:*:*:*:*:*:*
  • OR cpe:/a:jan_kara:linux_diskquota:3.01:pre7:*:*:*:*:*:*
  • OR cpe:/a:jan_kara:linux_diskquota:3.01:pre6:*:*:*:*:*:*
  • OR cpe:/a:jan_kara:linux_diskquota:3.01:pre5:*:*:*:*:*:*
  • OR cpe:/a:jan_kara:linux_diskquota:3.01:pre4:*:*:*:*:*:*
  • OR cpe:/a:jan_kara:linux_diskquota:3.01:pre3:*:*:*:*:*:*
  • OR cpe:/a:jan_kara:linux_diskquota:3.01:pre2:*:*:*:*:*:*
  • OR cpe:/a:jan_kara:linux_diskquota:2.0:*:*:*:*:*:*:*
  • AND
  • cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:5:*:client:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20123417
    V
    CVE-2012-3417
    2022-05-20
    oval:org.opensuse.security:def:33116
    P
    Security update for libvirt (Important)
    2022-01-10
    oval:org.opensuse.security:def:33021
    P
    Security update for libqt5-qtsvg (Moderate)
    2021-10-11
    oval:org.opensuse.security:def:30256
    P
    Security update for xen (Moderate)
    2021-10-07
    oval:org.opensuse.security:def:29431
    P
    Security update for webkit2gtk3 (Important)
    2021-10-06
    oval:org.opensuse.security:def:30219
    P
    Security update for libgcrypt (Important)
    2021-06-24
    oval:org.opensuse.security:def:29377
    P
    Security update for libX11 (Important)
    2021-06-08
    oval:org.opensuse.security:def:33630
    P
    Security update for fwupdate (Important)
    2021-04-08
    oval:org.opensuse.security:def:29480
    P
    Security update for openldap2 (Important)
    2021-03-03
    oval:org.opensuse.security:def:28866
    P
    Security update for xen (Important)
    2020-12-10
    oval:org.opensuse.security:def:33260
    P
    star on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28997
    P
    Security update for gnutls (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32795
    P
    t1lib on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29581
    P
    Security update for apache2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:33474
    P
    Security update for libesmtp
    2020-12-01
    oval:org.opensuse.security:def:29140
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:32807
    P
    xen on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33562
    P
    Security update for ImageMagick (Low)
    2020-12-01
    oval:org.opensuse.security:def:28786
    P
    Security update for mozilla-nss (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33173
    P
    libpoppler-glib4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34308
    P
    Security update for quota
    2020-12-01
    oval:org.opensuse.security:def:29537
    P
    Security update for MozillaFirefox (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33417
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:29083
    P
    Security update for dhcp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32796
    P
    tar on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33523
    P
    Security update for systemtap
    2020-12-01
    oval:org.opensuse.security:def:29224
    P
    Security update for php53 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32886
    P
    java-1_6_0-ibm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28785
    P
    Security update for mozilla-nspr (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33586
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:28797
    P
    Security update for openldap2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34268
    P
    Security update for procmail (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29519
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.mitre.oval:def:23266
    P
    ELSA-2013:0120: quota security and bug fix update (Low)
    2014-05-26
    oval:org.mitre.oval:def:21025
    P
    RHSA-2013:0120: quota security and bug fix update (Low)
    2014-02-17
    oval:com.redhat.rhsa:def:20130120
    P
    RHSA-2013:0120: quota security and bug fix update (Low)
    2013-01-08
    oval:com.ubuntu.precise:def:20123417000
    V
    CVE-2012-3417 on Ubuntu 12.04 LTS (precise) - low.
    2012-08-13
    oval:com.ubuntu.trusty:def:20123417000
    V
    CVE-2012-3417 on Ubuntu 14.04 LTS (trusty) - low.
    2012-08-13
    BACK
    jan_kara linux diskquota 3.16
    jan_kara linux diskquota 3.15
    jan_kara linux diskquota 3.14
    jan_kara linux diskquota 3.13
    jan_kara linux diskquota 3.12
    jan_kara linux diskquota 3.11
    jan_kara linux diskquota 3.10
    jan_kara linux diskquota 3.09
    jan_kara linux diskquota 3.08
    jan_kara linux diskquota 3.07
    jan_kara linux diskquota 3.06
    jan_kara linux diskquota 3.05
    jan_kara linux diskquota 3.04
    jan_kara linux diskquota 3.03
    jan_kara linux diskquota 3.02
    jan_kara linux diskquota 3.01
    jan_kara linux diskquota 3.01 pre9
    jan_kara linux diskquota 3.01 pre8
    jan_kara linux diskquota 3.01 pre7
    jan_kara linux diskquota 3.01 pre6
    jan_kara linux diskquota 3.01 pre5
    jan_kara linux diskquota 3.01 pre4
    jan_kara linux diskquota 3.01 pre3
    jan_kara linux diskquota 3.01 pre2
    jan_kara linux diskquota 2.0
    redhat enterprise linux 5
    redhat enterprise linux 5