First published: Mon Jul 25 2016(Updated: )
linenoise, as used in Redis before 3.2.3, uses world-readable permissions for .rediscli_history, which allows local users to obtain sensitive information by reading the file.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
Redis | <=3.2.2 | |
Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-7458 is considered a medium severity vulnerability due to its potential exposure of sensitive information.
To mitigate CVE-2013-7458, ensure that the permissions of the .rediscli_history file are set to restrict access to only authorized users.
CVE-2013-7458 affects Redis versions prior to 3.2.3.
Yes, local users can exploit CVE-2013-7458 to read sensitive information from the .rediscli_history file.
CVE-2013-7458 impacts Redis installations on Debian GNU/Linux version 8.0 and earlier versions.