The bootloader configuration module (pyanaconda/bootloader.py) in Anaconda uses 755 permissions for /etc/grub.d, which allows local users to obtain password hashes and conduct brute force password guessing attacks.
References
Configurations
History
21 Nov 2024, 01:38
Type | Values Removed | Values Added |
---|---|---|
References | () http://git.fedorahosted.org/git/?p=anaconda.git%3Ba=commit%3Bh=03ef13b625cc06873a924e0610340f8489fd92df - | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080188.html - | |
References | () http://www.openwall.com/lists/oss-security/2012/05/04/10 - Patch | |
References | () http://www.openwall.com/lists/oss-security/2012/05/04/12 - | |
References | () http://www.openwall.com/lists/oss-security/2024/01/15/3 - | |
References | () http://www.securityfocus.com/bid/53486 - | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=819031 - |
16 Jan 2024, 01:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
07 Nov 2023, 02:10
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2012-07-03 22:55
Updated : 2024-11-21 01:38
NVD link : CVE-2012-2314
Mitre link : CVE-2012-2314
CVE.ORG link : CVE-2012-2314
JSON object : View
Products Affected
fedoraproject
- anaconda
CWE
CWE-264
Permissions, Privileges, and Access Controls