PT-2001-1021 · Red Hat · Red Hat
Publicado
2001-04-25
·
Atualizado
2017-10-10
·
CVE-2001-0635
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Red Hat Linux version 7.1
Description
The issue allows a local attacker to gain additional privileges by reading sensitive information, such as passwords, from swap files created during installation due to insecure permissions. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be carried out locally.
Recommendations
For Red Hat Linux version 7.1, ensure that secure permissions are set on swap files to prevent unauthorized access to sensitive information. As a temporary workaround, consider restricting access to swap files until a proper fix is applied.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Red Hat