First published: Wed Apr 20 2016(Updated: )
tmpfiles.d/systemd.conf in systemd before 214 uses weak permissions for journal files under (1) /run/log/journal/%m and (2) /var/log/journal/%m, which allows local users to obtain sensitive information by reading these files.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Linux | =13.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9770 is considered a medium severity vulnerability due to its potential impact on sensitive information exposure.
To fix CVE-2014-9770, update your systemd package to version 214 or later to ensure proper permissions for journal files.
CVE-2014-9770 affects users of systemd versions prior to 214 on openSUSE 13.2.
CVE-2014-9770 enables local users to perform unauthorized reading of sensitive information from journal files.
The affected components in CVE-2014-9770 are the journal files located in /run/log/journal/%m and /var/log/journal/%m.