oss-sec mailing list archives

Re: [oCERT-2014-006] Ganeti insecure archive permission


From: cve-assign () mitre org
Date: Thu, 14 Aug 2014 12:10:24 -0400 (EDT)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Such archives are written with too lax permissions that make it
possible to access them as unprivileged user.

The configuration archive contains sensitive information, including
SSL keys for the inter-node RPC communication as well as the
credentials for the remote API (RAPI).

Use CVE-2014-5247.

- -- 
CVE assignment team, MITRE CVE Numbering Authority
M/S M300
202 Burlington Road, Bedford, MA 01730 USA
[ PGP key available through http://cve.mitre.org/cve/request_id.html ]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (SunOS)

iQEcBAEBAgAGBQJT7N2eAAoJEKllVAevmvmsrioH/33ive+8TrDkuY7hfT+4UsHK
GO6NH8c3omBnlNGXsdQ27xSBXzhol/kfW03/NcqBMK9SKPtcGMUk3GugMWAtv2yt
oDyvOP54QUtCS8ei7faqQLUjjW5zOxfrVJg14eaPPVYOdfatfoHOvVqcz7chqzUg
/RgoIvaslpRRK74s7CQdMOqQNOcfmD2KBxAUGNUUX/REx3QE2ojTUXTEL0dcTfyx
nn7HfoyikBE1VpHA+GS8Ew0Nqh5wTP+W0YGnL7AU+btY/BQR4aZJma567BnL63CC
Hb9pVneqCJq8HUjygmwgPDaDO6ivCnUuhZypg4kVg8ja37OysWfokzicK7kl03o=
=pveN
-----END PGP SIGNATURE-----


Current thread: