PT-2012-4722 · Open Networking Foundation · Openvswitch
Andreas Beckmann
+1
·
Publicado
2012-08-07
·
Atualizado
2024-06-15
·
CVE-2012-3449
CVSS v2.0
3.6
Baixa
| Vetor | AV:L/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Open vSwitch version 1.4.2
Description
The issue allows local users to delete and overwrite arbitrary files due to world-writable permissions for certain directories. Specifically, the directories
/var/lib/openvswitch/pki/controllerca/incoming/ and /var/lib/openvswitch/pki/switchca/incoming/ have insecure permissions.Recommendations
For Open vSwitch version 1.4.2, consider changing the permissions of the
/var/lib/openvswitch/pki/controllerca/incoming/ and /var/lib/openvswitch/pki/switchca/incoming/ directories to prevent world-writable access, thereby restricting the ability of local users to delete or overwrite files in these directories.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Openvswitch