Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-4982

Опубликовано: 13 июн. 2016
Источник: redhat
CVSS3: 2.5
CVSS2: 1.9

Описание

authd sets weak permissions for /etc/ident.key, which allows local users to obtain the key by leveraging a race condition between the creation of the key, and the chmod to protect it.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4authdWill not fix
Red Hat Enterprise Linux 5authdWill not fix
Red Hat Enterprise Linux 6authdWill not fix
Red Hat Enterprise Linux 7authdWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-732
https://bugzilla.redhat.com/show_bug.cgi?id=1346051authd insecure /etc/ident.key file creation

2.5 Low

CVSS3

1.9 Low

CVSS2

Связанные уязвимости

CVSS3: 4.7
nvd
больше 8 лет назад

authd sets weak permissions for /etc/ident.key, which allows local users to obtain the key by leveraging a race condition between the creation of the key, and the chmod to protect it.

CVSS3: 4.7
github
больше 3 лет назад

authd sets weak permissions for /etc/ident.key, which allows local users to obtain the key by leveraging a race condition between the creation of the key, and the chmod to protect it.

2.5 Low

CVSS3

1.9 Low

CVSS2