CVE-2012-4453: Low severity Dracut Project Dracut vulnerability
An information disclosure flaw was found in the way dracut, an initramfs root filesystem images generator, created initramfs images. When the root filesystem contained sensitive information (password based authentication for iSCSI systems or encrypted root filesystem crypttab password information), an attacker could use this flaw to obtain this information.
Acknowledgements:
This issue was discovered by Peter Jones of the Red Hat Installer Team.
Other sources
dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4453?
CVE-2012-4453 is classified as an information disclosure vulnerability.
How do I fix CVE-2012-4453?
To address CVE-2012-4453, upgrade to a version of dracut that is not vulnerable, specifically version 024 or later.
Which versions of dracut are affected by CVE-2012-4453?
CVE-2012-4453 affects dracut versions prior to 024.
What kind of information is disclosed due to CVE-2012-4453?
CVE-2012-4453 can disclose sensitive information such as passwords for iSCSI authentication or encrypted root filesystem crypttab passwords.
Which operating systems are affected by CVE-2012-4453?
CVE-2012-4453 affects Fedora versions 16 and 17, as well as Red Hat Enterprise Linux Desktop, Server, and Workstation version 6.0.