LWN.net Logo

rhncfg: information disclosure

Package(s):rhncfg CVE #(s):CVE-2012-2679
Created:February 4, 2013 Updated:February 6, 2013
Description: From the Red Hat bugzilla:

It was discovered that Red Hat Network Configuration Client set insecure (0644) permissions on the /var/log/rhncfg-actions file used to store (besides terminal) the output of different RHN Client actions (diff, verify etc.). A local attacker could use this flaw to obtain sensitive information, if the rhncfg-client diff action has been used to query differences between the (normally for unprivileged user not readable) config files stored by RHN and those, deployed on the system.

Alerts:
Fedora FEDORA-2013-1243 2013-02-03
Fedora FEDORA-2013-1229 2013-02-03
Fedora FEDORA-2013-1233 2013-02-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds