CVE-2013-7458: Infoleak
Published Jul 25, 2016
·Updated
linenoise, as used in Redis before 3.2.3, uses world-readable permissions for .redisclihistory, which allows local users to obtain sensitive information by reading the file.
Affected Software
2 affected components
Redislabs Redis<=3.2.2
Debian Debian Linux=8.0
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Jul 25, 2016
Data Sourced
via Debian·07:51 PM
SeverityAffected Software
Aug 10, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-7458?
CVE-2013-7458 is considered a medium severity vulnerability due to its potential exposure of sensitive information.
2
How do I fix CVE-2013-7458?
To mitigate CVE-2013-7458, ensure that the permissions of the .rediscli_history file are set to restrict access to only authorized users.
3
Which versions of Redis are affected by CVE-2013-7458?
CVE-2013-7458 affects Redis versions prior to 3.2.3.
4
Can local users exploit CVE-2013-7458?
Yes, local users can exploit CVE-2013-7458 to read sensitive information from the .rediscli_history file.
5
Are there any specific operating systems impacted by CVE-2013-7458?
CVE-2013-7458 impacts Redis installations on Debian GNU/Linux version 8.0 and earlier versions.