|
|
Log in / Subscribe / Register

Mageia alert MGASA-2016-0387 (dracut)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2016-0387: Updated dracut packages fix security vulnerability
Date:  Fri, 18 Nov 2016 00:41:24 +0100
Message-ID:  <20161117234124.5F3D09F7A2@duvel.mageia.org>

MGASA-2016-0387 - Updated dracut packages fix security vulnerability Publication date: 17 Nov 2016 URL: http://advisories.mageia.org/MGASA-2016-0387.html Type: security Affected Mageia releases: 5 CVE: CVE-2016-8637 Description: A local information disclosure issue was found in dracut when generating initramfs images with world-readable permissions when "early cpio" is used, such as when including microcode updates. Local attacker can use this to obtain sensitive information from these files, such as encryption keys or credentials (CVE-2016-8637). References: - https://bugs.mageia.org/show_bug.cgi?id=19731 - https://lists.fedoraproject.org/archives/list/package-ann... - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8637 SRPMS: - 5/core/dracut-038-21.1.mga5


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds