Описание
libcgroup up to and including 0.41 creates /var/log/cgred with mode 0666 regardless of the configured umask, leading to disclosure of information.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | libcgroup | Will not fix | ||
Red Hat Enterprise Linux 8 | libcgroup | Not affected | ||
Red Hat OpenShift Enterprise 3 | libcgroup | Not affected | ||
Red Hat Virtualization 4 | libcgroup | Not affected | ||
Red Hat Enterprise Linux 7 | libcgroup | Fixed | RHSA-2019:2047 | 06.08.2019 |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=1611119libcgroup: cgrulesengd creates log files with insecure permissions
EPSS
Процентиль: 69%
0.00617
Низкий
4.4 Medium
CVSS3
Связанные уязвимости
CVSS3: 8.1
ubuntu
около 7 лет назад
libcgroup up to and including 0.41 creates /var/log/cgred with mode 0666 regardless of the configured umask, leading to disclosure of information.
CVSS3: 8.1
nvd
около 7 лет назад
libcgroup up to and including 0.41 creates /var/log/cgred with mode 0666 regardless of the configured umask, leading to disclosure of information.
CVSS3: 8.1
debian
около 7 лет назад
libcgroup up to and including 0.41 creates /var/log/cgred with mode 06 ...
EPSS
Процентиль: 69%
0.00617
Низкий
4.4 Medium
CVSS3