First published: Fri Jul 26 2013(Updated: )
Race condition in Luci 0.26.0 creates /var/lib/luci/etc/luci.ini with world-readable permissions before restricting the permissions, which allows local users to read the file and obtain sensitive information such as "authentication secrets."
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Luci | =0.26.0 | |
Red Hat Enterprise Linux | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4481 is categorized as a medium severity vulnerability due to the potential exposure of sensitive information.
To fix CVE-2013-4481, update the Luci software to a version that restricts permissions on the configuration file appropriately.
CVE-2013-4481 affects Luci version 0.26.0 on Scientific Linux and Red Hat Enterprise Linux 6.0.
CVE-2013-4481 is a race condition vulnerability that allows unauthorized local access to sensitive configuration files.
CVE-2013-4481 can expose sensitive information such as authentication secrets stored in the luci.ini configuration file.