« Volver al listado

CVE-2012-0315

Estado: ModificadaAlta (9.3)—

Untrusted search path vulnerability in ALFTP before 5.31 allows local users to gain privileges via a Trojan horse executable file in a directory that is accessed for reading an extensionless file, as demonstrated by executing the README.exe file when a user attempts to access the README file.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-0315",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-02-22T13:54:03.553",
  "references": [
    {
      "url": "http://jvn.jp/en/jp/JVN85695061/995223/index.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://jvn.jp/en/jp/JVN85695061/index.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2012-000011",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://www.altools.jp/ETC/NEWS.aspx?mid=231&vidx=118",
      "tags": [
        "Broken Link"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://www.altools.jp/download.aspx",
      "tags": [
        "Broken Link",
        "Patch"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://jvn.jp/en/jp/JVN85695061/995223/index.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://jvn.jp/en/jp/JVN85695061/index.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2012-000011",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.altools.jp/ETC/NEWS.aspx?mid=231&vidx=118",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.altools.jp/download.aspx",
      "tags": [
        "Broken Link",
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Untrusted search path vulnerability in ALFTP before 5.31 allows local users to gain privileges via a Trojan horse executable file in a directory that is accessed for reading an extensionless file, as demonstrated by executing the README.exe file when a user attempts to access the README file."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de ruta de búsqueda no confiable en ALFTP antes de v5.31 permite a usuarios locales obtener privilegios mediante un archivo troyano ejecutable en un directorio al que se accede para leer un archivo sin extensión, tal y como se demuestra con la ejecución del archivo README.EXE cuando un usuario intenta acceder al archivo README."
    }
  ],
  "lastModified": "2026-06-16T23:37:05.853",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:estsoft:alftp:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4715D22D-5868-4A25-AB6E-0AC3E0FCDAED",
              "versionEndIncluding": "5.1"
            },
            {
              "criteria": "cpe:2.3:a:estsoft:alftp:4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DA854AAA-D9CF-479A-AEB2-89B91A9E5372"
            },
            {
              "criteria": "cpe:2.3:a:estsoft:alftp:4.1:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CF263169-AF6F-470A-BEB3-D5A03E9BE545"
            },
            {
              "criteria": "cpe:2.3:a:estsoft:alftp:4.1:beta2:*:en:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D305F6D8-A458-4B20-9989-39F08D79EA5A"
            },
            {
              "criteria": "cpe:2.3:a:estsoft:alftp:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9DB0095D-D7D6-425A-AFC1-2FE3C4796129"
            },
            {
              "criteria": "cpe:2.3:a:estsoft:alftp:5.1:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1E7CA781-E4EC-4CC2-8DA3-D14329DAE240"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorComment": "Per: http://cwe.mitre.org/data/definitions/426.html\r\n\r\n'CWE-426: Untrusted Search Path'",
  "sourceIdentifier": "vultures@jpcert.or.jp"
}