|
|
| |
|
| |
rhncfg: information disclosure
| Package(s): | rhncfg |
CVE #(s): | CVE-2012-2679
|
| Created: | February 4, 2013 |
Updated: | February 6, 2013 |
| Description: |
From the Red Hat bugzilla:
It was discovered that Red Hat Network Configuration Client set insecure (0644) permissions on the /var/log/rhncfg-actions file used to store (besides terminal) the output of different RHN Client actions (diff, verify etc.). A local attacker could use this flaw to obtain sensitive information, if the rhncfg-client diff action has been used to query differences between the (normally for unprivileged user not readable) config files stored by RHN and those, deployed on the system. |
| Alerts: |
|
( Log in to post comments)
|
|
|