Permissions, Privileges, and Access Controls in Augeas - CVE-2013-6412

 

Permissions, Privileges, and Access Controls in Augeas - CVE-2013-6412

Published: January 23, 2014 / Updated: July 28, 2020


Vulnerability identifier: #VU32579
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-6412
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local non-authenticated attacker to read and manipulate data.

The transform_save function in transform.c in Augeas 1.0.0 through 1.1.0 does not properly calculate the permission values when the umask contains a "7," which causes world-writable permissions to be used for new files and allows local users to modify the files via unspecified vectors.


Affected software

Augeas
Amazon Linux AMI
Fedora
augeas (Alpine package)
augeas

How to mitigate CVE-2013-6412

Install update from vendor's website.

Augeas - update to 1.2.0
augeas (Alpine package) - update to 1.0.0-r2
augeas - update to 1.2.0-1.el5

External References

Related Security Bulletins