Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/pki/controllerca/incoming/ and (2) /var/lib/openvswitch/pki/switchca/incoming/, which allows local users to delete and overwrite arbitrary files.
References
Configurations
History
21 Nov 2024, 01:40
Type | Values Removed | Values Added |
---|---|---|
References | () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=683665 - | |
References | () http://www.openwall.com/lists/oss-security/2012/08/02/6 - | |
References | () http://www.openwall.com/lists/oss-security/2012/08/03/6 - | |
References | () http://www.securityfocus.com/bid/54789 - | |
References | () http://www.securityfocus.com/bid/54794 - | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=845350 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/77417 - |
Information
Published : 2012-08-07 20:55
Updated : 2024-11-21 01:40
NVD link : CVE-2012-3449
Mitre link : CVE-2012-3449
CVE.ORG link : CVE-2012-3449
JSON object : View
Products Affected
openvswitch
- openvswitch
CWE
CWE-264
Permissions, Privileges, and Access Controls