CVE-2014-9770: Low severity openSUSE openSUSE vulnerability
tmpfiles.d/systemd.conf in systemd before 214 uses weak permissions for journal files under (1) /run/log/journal/%m and (2) /var/log/journal/%m, which allows local users to obtain sensitive information by reading these files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9770?
CVE-2014-9770 is considered a medium severity vulnerability due to its potential impact on sensitive information exposure.
How do I fix CVE-2014-9770?
To fix CVE-2014-9770, update your systemd package to version 214 or later to ensure proper permissions for journal files.
Who is affected by CVE-2014-9770?
CVE-2014-9770 affects users of systemd versions prior to 214 on openSUSE 13.2.
What type of attack does CVE-2014-9770 enable?
CVE-2014-9770 enables local users to perform unauthorized reading of sensitive information from journal files.
What are the affected components in CVE-2014-9770?
The affected components in CVE-2014-9770 are the journal files located in /run/log/journal/%m and /var/log/journal/%m.