Vulnerability CVE-2011-3589


Published: 2014-02-15

Description:
The Red Hat mkdumprd script for kexec-tools, as distributed in the kexec-tools 1.x before 1.102pre-154 and 2.x before 2.0.0-209 packages in Red Hat Enterprise Linux, uses world-readable permissions for vmcore files, which allows local users to obtain sensitive information by inspecting the file content, as demonstrated by a search for a root SSH key.

Type:

CWE-310

(Cryptographic Issues)

CVSS2 => (AV:A/AC:M/Au:N/C:C/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5.7/10
6.9/10
5.5/10
Exploit range
Attack complexity
Authentication
Adjacent network
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
None
None
Affected software
Redhat -> Kexec-tools 

 References:
https://bugzilla.redhat.com/show_bug.cgi?id=716439
http://rhn.redhat.com/errata/RHSA-2012-0152.html
http://rhn.redhat.com/errata/RHSA-2011-1532.html

Copyright 2024, cxsecurity.com

 

Back to Top