CVE-2013-4481: Race Condition
Race condition in Luci 0.26.0 creates /var/lib/luci/etc/luci.ini with world-readable permissions before restricting the permissions, which allows local users to read the file and obtain sensitive information such as "authentication secrets."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4481?
CVE-2013-4481 is categorized as a medium severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2013-4481?
To fix CVE-2013-4481, update the Luci software to a version that restricts permissions on the configuration file appropriately.
Which systems are affected by CVE-2013-4481?
CVE-2013-4481 affects Luci version 0.26.0 on Scientific Linux and Red Hat Enterprise Linux 6.0.
What type of vulnerability is CVE-2013-4481?
CVE-2013-4481 is a race condition vulnerability that allows unauthorized local access to sensitive configuration files.
What information can be compromised by CVE-2013-4481?
CVE-2013-4481 can expose sensitive information such as authentication secrets stored in the luci.ini configuration file.