CVE-2013-6412
Published: 23 January 2014
The transform_save function in transform.c in Augeas 1.0.0 through 1.1.0 does not properly calculate the permission values when the umask contains a "7," which causes world-writable permissions to be used for new files and allows local users to modify the files via unspecified vectors.
Notes
Author | Note |
---|---|
seth-arnold | This is due to an incomplete fix for CVE-2012-0786. |
Priority
Status
Package | Release | Status |
---|---|---|
augeas Launchpad, Ubuntu, Debian |
lucid |
Ignored
(end of life)
|
precise |
Ignored
(end of life)
|
|
quantal |
Not vulnerable
|
|
raring |
Ignored
(end of life)
|
|
saucy |
Ignored
(end of life)
|
|
trusty |
Not vulnerable
(1.2.0-0ubuntu1.1)
|
|
upstream |
Needed
|
|
utopic |
Not vulnerable
(1.2.0-0ubuntu2)
|
|
vivid |
Not vulnerable
(1.3.0-0ubuntu1)
|
|
wily |
Not vulnerable
(1.3.0-0ubuntu1)
|
|
xenial |
Not vulnerable
(1.3.0-0ubuntu1)
|
|
yakkety |
Not vulnerable
(1.3.0-0ubuntu1)
|
|
zesty |
Not vulnerable
(1.3.0-0ubuntu1)
|
|
Patches: other: https://github.com/domcleal/augeas/commit/f4f9fa61c0e0e5a10e19e0f48df31022e842dfcc |