Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-2690

Опубликовано: 08 фев. 2012
Источник: redhat
CVSS2: 1.2
EPSS Низкий

Описание

virt-edit in libguestfs before 1.18.0 does not preserve the permissions from the original file and saves the new file with world-readable permissions when editing, which might allow local guest users to obtain sensitive information.

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=831117libguestfs: virt-edit creates a new file, when it is used leading to loss of file attributes (permissions, owner, SELinux context etc.)

EPSS

Процентиль: 15%
0.0005
Низкий

1.2 Low

CVSS2

Связанные уязвимости

ubuntu
около 13 лет назад

virt-edit in libguestfs before 1.18.0 does not preserve the permissions from the original file and saves the new file with world-readable permissions when editing, which might allow local guest users to obtain sensitive information.

nvd
около 13 лет назад

virt-edit in libguestfs before 1.18.0 does not preserve the permissions from the original file and saves the new file with world-readable permissions when editing, which might allow local guest users to obtain sensitive information.

debian
около 13 лет назад

virt-edit in libguestfs before 1.18.0 does not preserve the permission ...

github
больше 3 лет назад

virt-edit in libguestfs before 1.18.0 does not preserve the permissions from the original file and saves the new file with world-readable permissions when editing, which might allow local guest users to obtain sensitive information.

oracle-oval
около 13 лет назад

ELSA-2012-0774: libguestfs security, bug fix, and enhancement update (LOW)

EPSS

Процентиль: 15%
0.0005
Низкий

1.2 Low

CVSS2