Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2014-4039

Published: 17 June 2014

ppc64-diag 2.6.1 uses 0775 permissions for /tmp/diagSEsnap and does not properly restrict permissions for /tmp/diagSEsnap/snapH.tar.gz, which allows local users to obtain sensitive information by reading files in this archive, as demonstrated by /var/log/messages and /etc/yaboot.conf.

Notes

AuthorNote
sbeattie
in trusty, powerpc-utils does not contain the snap script, so
no file generated
in yakkety and newer, powerpc-utils dropped the snap script, so
no file generated there; yakkety has a patch applied by debian to
adjust the directory permissions as well, but it's a moot point.
in xenial, the snap script refuses to run on Ubuntu, due to
not supporting the distro, and again won't create the file.

Priority

Medium

Status

Package Release Status
ppc64-diag
Launchpad, Ubuntu, Debian
lucid Does not exist

precise Does not exist

saucy Does not exist

trusty Does not exist
(trusty was not-affected [no snap in powerpc-utils])
upstream Needs triage

utopic Ignored
(end of life)
vivid Ignored
(end of life)
wily Ignored
(end of life)
xenial Not vulnerable
(snap refuses to run)