oss-sec mailing list archives

CVE Request: netfilter-persistent: (local) information leak due to world-readable rules files


From: Salvatore Bonaccorso <carnil () debian org>
Date: Tue, 5 Jan 2016 11:13:46 +0100

Hi,

iptables-persistent (in Debian) is a loader for netfilter configuration
using a plugin-based architecture.

iptables-persistent is vulnerable to a (local) information leak due to
world-readable rules files. It was reported in Debian in

https://bugs.debian.org/764645

And fixed via

https://anonscm.debian.org/cgit/collab-maint/iptables-persistent.git/commit/?id=37905034f07e94c4298a1762b39b7bbd4063c0df

Could you assign a CVE for this issue?

p.s.: There is a fork of iptables-persistent. But I have not checked
if the fork https://github.com/zertrin/iptables-persistent is as well
affected by this issue).

Regards,
Salvatore


Current thread: