PT-2001-1021 · Red Hat · Red Hat
Published
2001-04-25
·
Updated
2017-10-10
·
CVE-2001-0635
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Red Hat Linux version 7.1
Description
The issue allows a local attacker to gain additional privileges by reading sensitive information, such as passwords, from swap files created during installation due to insecure permissions. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be carried out locally.
Recommendations
For Red Hat Linux version 7.1, ensure that secure permissions are set on swap files to prevent unauthorized access to sensitive information. As a temporary workaround, consider restricting access to swap files until a proper fix is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat