Secunia CSI Agent 6.0.0.15017 and earlier, 6.0.1.1007 and earlier, and 7.0.0.21 and earlier, when running on Red Hat Linux, uses world-readable and world-writable permissions for /etc/csia_config.xml, which allows local users to change CSI Agent configuration by modifying this file.
References
Link | Resource |
---|---|
http://secunia.com/vulnerability_scanning/corporate/release-history/ | Third Party Advisory |
http://secunia.com/advisories/56380 | Third Party Advisory |
http://www.securityfocus.com/bid/64775 | Third Party Advisory VDB Entry |
http://osvdb.org/101901 | Broken Link |
https://exchange.xforce.ibmcloud.com/vulnerabilities/90230 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2014-01-25 17:55
Updated : 2018-12-13 10:21
NVD link : CVE-2013-5364
Mitre link : CVE-2013-5364
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
secunia
- csi_agent
redhat
- enterprise_linux