PT-2001-1021 · Red Hat · Red Hat

Publicado

2001-04-25

·

Atualizado

2017-10-10

·

CVE-2001-0635

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Red Hat Linux version 7.1
Description The issue allows a local attacker to gain additional privileges by reading sensitive information, such as passwords, from swap files created during installation due to insecure permissions. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be carried out locally.
Recommendations For Red Hat Linux version 7.1, ensure that secure permissions are set on swap files to prevent unauthorized access to sensitive information. As a temporary workaround, consider restricting access to swap files until a proper fix is applied.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-07807
BDU:2015-07815
CVE-2001-0635

Produtos afetados

Red Hat