oss-sec mailing list archives
Re: Question about world readable config files and commented warnings
From: cve-assign () mitre org
Date: Tue, 30 Jun 2015 17:40:59 -0400 (EDT)
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
the specific case of: Configuration file takes a password and has world readable permissions by default (and let's assume no explicit warning in the comments in the config file).
CVE covers the CWE-276 ("Incorrect Default Permissions") issue and similar weak-permissions issues as long as a security boundary is crossed. A security boundary would be crossed on a general-purpose, multi-user computer, as well as on most other multi-user platforms. Typically there is an exception in the case of an embedded device where a multi-user level of access control isn't set up and wasn't ever intended or documented by the vendor. For example, obtaining an OS image of an arbitrary embedded device, and noting that it has a filesystem that supports file permissions, doesn't necessarily imply anything about what those permissions were supposed to be. - -- CVE assignment team, MITRE CVE Numbering Authority M/S M300 202 Burlington Road, Bedford, MA 01730 USA [ PGP key available through http://cve.mitre.org/cve/request_id.html ] -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.14 (SunOS) iQEcBAEBAgAGBQJVkwvZAAoJEKllVAevmvmsjSsIALdZzYAdIBfjW1UlQEfKwP7Z 7njDEjKjIHpIWOnH9S+LZyYfMBrCZT9mLtRPUzpFwNOuyV/SZBL7MBRJScyDlpQ4 INdBMNt+gN9NPbqs/ZqZgvA3LWSXSI5L8yI1DmM0Xx2/i2rZ6V6TXoH7u6+uiXDM fGA/j8M7ePyXor4dwFx0kZo8LshzE4gTx12tr1u7TIcmMzyyPCTA+LOG7MbOeBFh YICPwZPI99hGieeLmRu7+S8Cyd8pqyz4h7v1xkTheyEqFUdyp8LvuSO02uJYTeC6 8Yc/bp+QZl11OBRFDsAoIo2WBr+zASDRT60eJnvfK+v1IRmCZMqAo9fadUk8m58= =YCxq -----END PGP SIGNATURE-----
Current thread:
- Question about world readable config files and commented warnings Kurt Seifried (Jun 29)
- Re: Question about world readable config files and commented warnings gremlin (Jun 29)
- Re: Question about world readable config files and commented warnings Kurt Seifried (Jun 30)
- Re: Question about world readable config files and commented warnings vladz (Jun 30)
- Re: Question about world readable config files and commented warnings Seth Arnold (Jun 30)
- Re: Question about world readable config files and commented warnings Kurt Seifried (Jun 30)
- Re: Question about world readable config files and commented warnings gremlin (Jun 29)
- Re: Question about world readable config files and commented warnings cve-assign (Jun 30)
- Re: Question about world readable config files and commented warnings Kurt Seifried (Jun 30)
- Re: Re: Question about world readable config files and commented warnings Seth Arnold (Jun 30)
- Re: Question about world readable config files and commented warnings cve-assign (Jun 30)
- Re: Question about world readable config files and commented warnings Kurt Seifried (Jun 30)
- Re: Question about world readable config files and commented warnings cve-assign (Jun 30)
- Re: Question about world readable config files and commented warnings Kurt Seifried (Jun 30)