Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-4453

Опубликовано: 27 сент. 2012
Источник: redhat
CVSS2: 5.4
EPSS Низкий

Описание

dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.

It was discovered that dracut created initramfs images as world readable. A local user could possibly use this flaw to obtain sensitive information from these files, such as iSCSI authentication passwords, encrypted root file system crypttab passwords, or other information.

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=859448dracut: Creates initramfs images with world-readable permissions (information disclosure)

EPSS

Процентиль: 10%
0.00039
Низкий

5.4 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 13 лет назад

dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.

nvd
почти 13 лет назад

dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.

debian
почти 13 лет назад

dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 ...

github
больше 3 лет назад

dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.

oracle-oval
больше 11 лет назад

ELSA-2013-1674: dracut security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 10%
0.00039
Низкий

5.4 Medium

CVSS2