PT-2001-1021 · Red Hat · Red Hat

Published

2001-04-25

·

Updated

2017-10-10

·

CVE-2001-0635

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Red Hat Linux version 7.1
Description The issue allows a local attacker to gain additional privileges by reading sensitive information, such as passwords, from swap files created during installation due to insecure permissions. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be carried out locally.
Recommendations For Red Hat Linux version 7.1, ensure that secure permissions are set on swap files to prevent unauthorized access to sensitive information. As a temporary workaround, consider restricting access to swap files until a proper fix is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-07807
BDU:2015-07815
CVE-2001-0635

Affected Products

Red Hat