PT-2019-1891 · Microsoft+4 · Azure Windows Azure Linux Agent+4
Published
2019-02-28
·
Updated
2020-08-24
·
CVE-2019-0804
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Azure Windows Azure Linux Agent (affected versions not specified)
Description
An information disclosure issue exists due to improper permission assignment for swap files by the Azure WaLinuxAgent. This could allow a remote attacker to gain unauthorized access to information by reading swap files as an arbitrary user.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Azure Windows Azure Linux Agent
Centos
Red Hat
Suse
Ubuntu