First published: Thu Nov 18 2010(Updated: )
plymouth-pretrigger.sh in dracut and udev, when running on Fedora 13 and 14, sets weak permissions for the /dev/systty device file, which allows remote authenticated users to read terminal data from tty0 for local users.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dracut | ||
Uwamp | ||
Fedora | =13 | |
Fedora | =14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2010-4176 is considered moderate due to the potential exposure of sensitive terminal data.
To fix CVE-2010-4176, update to the latest version of Dracut and Udev that addresses the permissions issue for the /dev/systty device file.
CVE-2010-4176 was reported by security researcher Tavis Ormandy.
CVE-2010-4176 affects Fedora 13 and Fedora 14.
CVE-2010-4176 affects the permission settings of the /dev/systty device file, allowing potential unauthorized access to terminal data.