plymouth-pretrigger.sh in dracut and udev, when running on Fedora 13 and 14, sets weak permissions for the /dev/systty device file, which allows remote authenticated users to read terminal data from tty0 for local users.
References
Link | Resource |
---|---|
http://secunia.com/advisories/42342 | Not Applicable |
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051418.html | Mailing List Third Party Advisory |
http://www.vupen.com/english/advisories/2010/3062 | Permissions Required |
http://www.securityfocus.com/bid/45046 | Third Party Advisory VDB Entry |
https://bugzilla.redhat.com/show_bug.cgi?id=654489 | Issue Tracking Third Party Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=654935 | Issue Tracking Third Party Advisory |
http://www.vupen.com/english/advisories/2010/3110 | Permissions Required |
http://secunia.com/advisories/42451 | Not Applicable |
http://lists.fedoraproject.org/pipermail/package-announce/2010-December/051755.html | Mailing List Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2010-12-07 14:00
Updated : 2022-06-03 08:09
NVD link : CVE-2010-4176
Mitre link : CVE-2010-4176
JSON object : View
CWE
CWE-276
Incorrect Default Permissions
Products Affected
udev_project
- udev
dracut_project
- dracut
fedoraproject
- fedora