REDHAT-BUG-845350: Low severity Open vSwitch openvswitch-pki vulnerability
Andreas Beckmann debian reports:
openvswitch-pki creates the following world writable directories during installation:
drwx-wx-wx 2 root root 40 Aug 1 05:32 /var/lib/openvswitch/pki/controllerca/incoming drwx-wx-wx 2 root root 40 Aug 1 05:32 /var/lib/openvswitch/pki/switchca/incoming
Even if an ordinary local user cannot list the contents of the directory, he may correctly derive/guess filenames (unless they are exclusively $(mktemp)) and delete and replace files in there.
I don't know how openvswitch-pki works, how it uses this directory, what probelms could possibly arise out of this.
References: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=683665
Please note on Fedora 16 and 17 run the command:
/usr/bin/ovs-pki --force init
to create the directories.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-845350?
The severity of REDHAT-BUG-845350 is considered high due to the creation of world writable directories that could lead to unauthorized access or modification.
How do I fix REDHAT-BUG-845350?
To fix REDHAT-BUG-845350, change the permissions of the affected directories to restrict write access to authorized users only.
Which software is affected by REDHAT-BUG-845350?
REDHAT-BUG-845350 affects the Open vSwitch package specifically the openvswitch-pki component.
What are the implications of REDHAT-BUG-845350?
The implications of REDHAT-BUG-845350 include potential security risks such as unauthorized access to sensitive PKI materials.
When was REDHAT-BUG-845350 reported?
REDHAT-BUG-845350 was reported on August 1.