CVE-2013-4367: High severity ovirt engine vulnerability
ovirt-engine 3.2 running on Linux kernel 3.1 and newer creates certain files world-writeable due to an upstream kernel change which impacted how python's os.chmod() works when passed a mode of '-1'.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4367?
The severity of CVE-2013-4367 is high.
What software is affected by CVE-2013-4367?
Ovirt Ovirt-engine 3.2 and Linux kernel 3.1 are affected by CVE-2013-4367.
How does CVE-2013-4367 affect ovirt-engine 3.2?
ovirt-engine 3.2 creates certain files world-writeable due to an upstream kernel change which impacted how python's os.chmod() works when passed a mode of '-1'.
How can I fix CVE-2013-4367?
Upgrade ovirt-engine to a version that is not affected or apply the necessary patches if available.
Where can I find more information about CVE-2013-4367?
You can find more information about CVE-2013-4367 at the following references: [Red Hat Security Advisory](https://access.redhat.com/security/cve/cve-2013-4367) and [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4367).