First published: Fri Nov 01 2019(Updated: )
ovirt-engine 3.2 running on Linux kernel 3.1 and newer creates certain files world-writeable due to an upstream kernel change which impacted how python's os.chmod() works when passed a mode of '-1'.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ovirt Ovirt-engine | =3.2 | |
Linux Linux kernel | =3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-4367 is high.
Ovirt Ovirt-engine 3.2 and Linux kernel 3.1 are affected by CVE-2013-4367.
ovirt-engine 3.2 creates certain files world-writeable due to an upstream kernel change which impacted how python's os.chmod() works when passed a mode of '-1'.
Upgrade ovirt-engine to a version that is not affected or apply the necessary patches if available.
You can find more information about CVE-2013-4367 at the following references: [Red Hat Security Advisory](https://access.redhat.com/security/cve/cve-2013-4367) and [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4367).