A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio' is used, such as when including microcode updates. Local attacker can use this to obtain sensitive information from these files, such as encryption keys or credentials.
References
Link | Resource |
---|---|
http://seclists.org/oss-sec/2016/q4/352 | Exploit Mailing List Third Party Advisory |
http://www.securityfocus.com/bid/94128 | Third Party Advisory VDB Entry |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8637 | Exploit Issue Tracking Third Party Advisory |
https://github.com/dracutdevs/dracut/commit/0db98910a11c12a454eac4c8e86dc7a7bbc764a4 | Patch Third Party Advisory |
http://seclists.org/oss-sec/2016/q4/352 | Exploit Mailing List Third Party Advisory |
http://www.securityfocus.com/bid/94128 | Third Party Advisory VDB Entry |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8637 | Exploit Issue Tracking Third Party Advisory |
https://github.com/dracutdevs/dracut/commit/0db98910a11c12a454eac4c8e86dc7a7bbc764a4 | Patch Third Party Advisory |
Configurations
History
21 Nov 2024, 02:59
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 2.1
v3 : 5.0 |
References | () http://seclists.org/oss-sec/2016/q4/352 - Exploit, Mailing List, Third Party Advisory | |
References | () http://www.securityfocus.com/bid/94128 - Third Party Advisory, VDB Entry | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8637 - Exploit, Issue Tracking, Third Party Advisory | |
References | () https://github.com/dracutdevs/dracut/commit/0db98910a11c12a454eac4c8e86dc7a7bbc764a4 - Patch, Third Party Advisory |
Information
Published : 2018-08-01 13:29
Updated : 2024-11-21 02:59
NVD link : CVE-2016-8637
Mitre link : CVE-2016-8637
CVE.ORG link : CVE-2016-8637
JSON object : View
Products Affected
dracut_project
- dracut