PT-1996-1073 · Debian+1 · Cpio+1
Publicado
1996-07-16
·
Atualizado
2017-10-19
·
CVE-1999-1572
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
cpio on FreeBSD version 2.1.0
cpio on Debian GNU/Linux version 3.0
Description
The issue allows local users to read or overwrite files created by cpio due to the use of a 0 umask when creating files with the -O or -F options, resulting in files being created with mode 0666.
Recommendations
For cpio on FreeBSD version 2.1.0, consider changing the umask to a more restrictive setting to prevent unauthorized access to files created with the -O or -F options.
For cpio on Debian GNU/Linux version 3.0, consider changing the umask to a more restrictive setting to prevent unauthorized access to files created with the -O or -F options.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Red Hat
Cpio