PT-2014-1856 · Augeas+4 · Augeas+4

Domcleal

·

Published

2014-01-20

·

Updated

2014-02-24

·

CVE-2013-6412

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Augeas versions 1.0.0 through 1.1.0
Description The issue is related to the transform save function in transform.c which does not properly calculate permission values when the umask contains a "7". This causes world-writable permissions to be used for new files, allowing local users to modify the files. The exploitation of this issue can lead to a violation of confidentiality, integrity, and availability of protected information. It can be exploited locally.
Recommendations For Augeas versions 1.0.0 through 1.1.0, consider updating to a version where the transform save function is properly fixed to handle permission values correctly. As a temporary workaround, restrict access to files created by the transform save function to minimize the risk of exploitation. Avoid using the umask with a value containing "7" in the affected versions until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1235
BDU:2015-06702
BDU:2015-06703
BDU:2015-06704
BDU:2015-06705
BDU:2015-09069
BDU:2015-09070
BDU:2015-09071
BDU:2015-09072
CESA-2014_0044
CVE-2013-6412
DLA-28-1
MGASA-2014-0058
RHSA-2014:0044
RHSA-2014_0044

Affected Products

Alt Linux
Augeas
Centos
Red Hat
Suse