Permissions, Privileges, and Access Controls in Augeas - CVE-2013-6412
Published: January 23, 2014 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a local non-authenticated attacker to read and manipulate data.
The transform_save function in transform.c in Augeas 1.0.0 through 1.1.0 does not properly calculate the permission values when the umask contains a "7," which causes world-writable permissions to be used for new files and allows local users to modify the files via unspecified vectors.
Affected software
Amazon Linux AMI
Fedora
augeas (Alpine package)
augeas
How to mitigate CVE-2013-6412
augeas (Alpine package) - update to 1.0.0-r2
augeas - update to 1.2.0-1.el5