1.9
CVSSv2

CVE-2013-4481

Published: 23/11/2013 Updated: 22/04/2019
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Race condition in Luci 0.26.0 creates /var/lib/luci/etc/luci.ini with world-readable permissions before restricting the permissions, which allows local users to read the file and obtain sensitive information such as "authentication secrets."

Vulnerable Product Search on Vulmon Subscribe to Product

scientificlinux luci 0.26.0

redhat enterprise linux 6.0

Vendor Advisories

Synopsis Moderate: luci security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic Updated luci packages that fix two security issues, several bugs, and addtwo enhancements are now available for Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated this updat ...