SB2014020521 - Permissions, Privileges, and Access Controls in augeas (Alpine package)
Published: February 5, 2014
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2013-6412)
The vulnerability allows a local non-authenticated attacker to read and manipulate data.
The transform_save function in transform.c in Augeas 1.0.0 through 1.1.0 does not properly calculate the permission values when the umask contains a "7," which causes world-writable permissions to be used for new files and allows local users to modify the files via unspecified vectors.
Remediation
Install update from vendor's website.