CVE-2012-0787: Augeas

Low severity, CVSS 3.7. EPSS: 0.4% chance of exploitation in the next 30 days.

The clone_file function in transfer.c in Augeas before 1.0.0, when copy_if_rename_fails is set and EXDEV or EBUSY is returned by the rename function, allows local users to overwrite arbitrary files and obtain sensitive information via a bind mount on the (1) .augsave or (2) destination file when using the backup save option, or (3) .augnew file when using the newfile save option.

Affected products

  • Augeas Augeas: up to and including 0.10.0; version 0.0.1 only; version 0.0.2 only; version 0.0.3 only; version 0.0.4 only; version 0.0.5 only; …
  • Red Hat Enterprise Linux: version 6.0 only

Published 2013-11-23. Last modified 2026-06-16.