CVE-2013-6494: Low severity fedup vulnerability
fedup 0.9.0 in Fedora 19, 20, and 21 uses a temporary directory with a static name for its download cache, which allows local users to cause a denial of service (prevention of system updates).
Other sources
Michael Scherer of Red Hat reports:
While trying to upgrade my F19 to F20 using fedup, I noticed that it use a directory in /var/tmp/, with a fixed known name.
cachedir = '/var/tmp/fedora-upgrade'
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6494?
CVE-2013-6494 has a medium severity rating as it allows local users to cause a denial of service.
How do I fix CVE-2013-6494?
To fix CVE-2013-6494, ensure that the fedup software is updated to a version that uses a unique temporary directory.
Which versions of fedup are affected by CVE-2013-6494?
Fedup version 0.9.0 is affected by CVE-2013-6494 in Fedora 19, 20, and 21.
Can CVE-2013-6494 be exploited remotely?
No, CVE-2013-6494 can only be exploited by local users on the affected systems.
What types of systems are impacted by CVE-2013-6494?
CVE-2013-6494 impacts systems running Fedora 19, 20, and 21 that use fedup version 0.9.0.