CVE-2011-1934: Infoleak
Published Nov 26, 2019
·Updated
lilo-uuid-diskid causes lilo.conf to be world-readable in lilo 23.1.
Affected Software
5 affected components
debian/lilo
Lilo Project Lilo=23.1
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Event History
Nov 26, 2019
CVE Published
via MITRE·09:03 PM
Data Sourced
via MITRE·09:03 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2011-1934?
CVE-2011-1934 is considered to have a moderate severity due to the exposure of sensitive configuration information.
2
How do I fix CVE-2011-1934?
To fix CVE-2011-1934, ensure that the permissions of the lilo.conf file are set to be less permissive, ideally restricting access to only the root user.
3
Which versions of LILO are affected by CVE-2011-1934?
CVE-2011-1934 specifically affects version 23.1 of LILO.
4
Is LILO 23.1 compatible with all versions of Debian?
LILO 23.1 is known to be compatible with Debian versions 8.0, 9.0, and 10.0.
5
What potential risks does CVE-2011-1934 pose to system security?
CVE-2011-1934 poses a risk by making the lilo configuration file world-readable, potentially exposing sensitive boot configurations to unauthorized users.