Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog
Консоль
Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog

exploitDog

debian Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

CVE-2012-2690

ΠžΠΏΡƒΠ±Π»ΠΈΠΊΠΎΠ²Π°Π½ΠΎ: 29 июн. 2012
Π˜ΡΡ‚ΠΎΡ‡Π½ΠΈΠΊ: debian
EPSS Низкий

ОписаниС

virt-edit in libguestfs before 1.18.0 does not preserve the permissions from the original file and saves the new file with world-readable permissions when editing, which might allow local guest users to obtain sensitive information.

ΠŸΠ°ΠΊΠ΅Ρ‚Ρ‹

ΠŸΠ°ΠΊΠ΅Ρ‚Π‘Ρ‚Π°Ρ‚ΡƒΡΠ’Π΅Ρ€ΡΠΈΡ исправлСнияРСлизВип
libguestfsfixed1:1.18.0-1package

ΠŸΡ€ΠΈΠΌΠ΅Ρ‡Π°Π½ΠΈΡ

  • Upstream patch https://www.redhat.com/archives/libguestfs/2012-February/msg00034.html

  • https://www.redhat.com/archives/libguestfs/2012-February/msg00033.html

  • https://bugzilla.redhat.com/show_bug.cgi?id=788642

  • https://www.openwall.com/lists/oss-security/2012/06/11/1

  • https://www.openwall.com/lists/oss-security/2012/06/11/5

EPSS

ΠŸΡ€ΠΎΡ†Π΅Π½Ρ‚ΠΈΠ»ΡŒ: 16%
0.0005
Низкий

БвязанныС уязвимости

ubuntu
ΠΏΠΎΡ‡Ρ‚ΠΈ 14 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

virt-edit in libguestfs before 1.18.0 does not preserve the permissions from the original file and saves the new file with world-readable permissions when editing, which might allow local guest users to obtain sensitive information.

redhat
ΠΎΠΊΠΎΠ»ΠΎ 14 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

virt-edit in libguestfs before 1.18.0 does not preserve the permissions from the original file and saves the new file with world-readable permissions when editing, which might allow local guest users to obtain sensitive information.

nvd
ΠΏΠΎΡ‡Ρ‚ΠΈ 14 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

virt-edit in libguestfs before 1.18.0 does not preserve the permissions from the original file and saves the new file with world-readable permissions when editing, which might allow local guest users to obtain sensitive information.

github
ΠΏΠΎΡ‡Ρ‚ΠΈ 4 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄

virt-edit in libguestfs before 1.18.0 does not preserve the permissions from the original file and saves the new file with world-readable permissions when editing, which might allow local guest users to obtain sensitive information.

oracle-oval
ΠΏΠΎΡ‡Ρ‚ΠΈ 14 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

ELSA-2012-0774: libguestfs security, bug fix, and enhancement update (LOW)

EPSS

ΠŸΡ€ΠΎΡ†Π΅Π½Ρ‚ΠΈΠ»ΡŒ: 16%
0.0005
Низкий
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡ‚ΡŒ CVE-2012-2690