CVE-2012-3292
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
07/06/2012
Last modified:
11/04/2025
Description
The GridFTP in Globus Toolkit (GT) before 5.2.2, when certain autoconf macros are defined, does not properly check the return value from the getpwnam_r function, which might allow remote attackers to gain privileges by logging in with a user that does not exist, which causes GridFTP to run as the last user in the password file.
Impact
Base Score 2.0
7.60
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:globus:globus_toolkit:*:*:*:*:*:*:*:* | 5.2.1 (including) | |
| cpe:2.3:a:globus:globus_toolkit:2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:globus:globus_toolkit:2.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:globus:globus_toolkit:2.4.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:globus:globus_toolkit:3.0.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:globus:globus_toolkit:3.2.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:globus:globus_toolkit:4.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:globus:globus_toolkit:4.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:globus:globus_toolkit:4.0.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:globus:globus_toolkit:4.0.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:globus:globus_toolkit:4.0.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:globus:globus_toolkit:4.0.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:globus:globus_toolkit:4.0.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:globus:globus_toolkit:4.0.7:*:*:*:*:*:*:* | ||
| cpe:2.3:a:globus:globus_toolkit:4.0.8:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://jira.globus.org/browse/GT-195
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081787.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081791.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081797.html
- http://www.debian.org/security/2012/dsa-2523
- http://jira.globus.org/browse/GT-195
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081787.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081791.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081797.html
- http://www.debian.org/security/2012/dsa-2523



