CVE-2012-5635: Gluster Glusterfs

Low severity, CVSS 2.1. EPSS: 0.3% chance of exploitation in the next 30 days.

The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and possibly other vectors, different vulnerabilities than CVE-2012-4417.

Affected products

  • Gluster Glusterfs: affected versions not specified
  • Red Hat Storage Management Console: version 2.0 only
  • Red Hat Storage Native Client: affected versions not specified
  • Red Hat Storage Server: version 2.0 only

Published 2013-04-09. Last modified 2026-06-16.