VulnerabilityModified
CVE-2012-4453
dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.
LOW 2.1EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.36% probability · 30th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-276
- Affected
- dracut project/dracut · fedoraproject/fedora · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation
- Source
- secalert@redhat.com
References
- http://git.kernel.org/?p=boot/dracut/dracut.git%3Ba=commit%3Bh=e1b48995c26c4f06d1a71
- http://rhn.redhat.com/errata/RHSA-2013-1674.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2012/09/27/3Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2012/09/27/4Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2012/09/27/6Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/55713Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=859448Issue Tracking, Patch, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79258Third Party Advisory, VDB Entry
- http://git.kernel.org/?p=boot/dracut/dracut.git%3Ba=commit%3Bh=e1b48995c26c4f06d1a71
- http://rhn.redhat.com/errata/RHSA-2013-1674.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2012/09/27/3Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2012/09/27/4Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2012/09/27/6Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/55713Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=859448Issue Tracking, Patch, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79258Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.