First published: Thu Feb 14 2013(Updated: )
In InfraStack/OSDependent/Linux/InfraStackModules/TraceModule/TraceModule.c, function Trace_OpenLogFile, the log file (typically /var/log/wimax/wimaxd.log) is chmod'ed to 0666. Log files should not be world-writable. I'm not sure if this log file should even be world-readable (see <a class="bz_bug_link bz_status_CLOSED bz_closed bz_public " title="CLOSED EOL - CVE-2013-4217 wimax (OSAL crypt module): By setting encrypted password writes unencrypted passwords to log files" href="show_bug.cgi?id=911121">bug 911121</a>). It's probably best to restrict permissions on the /var/log/wimax directory, too.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel WiMAX Network Service | <=1.5.2 | |
Intel WiMAX Network Service | =1.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.