plymouth-pretrigger.sh in dracut and udev, when running on Fedora 13 and 14, sets weak permissions for the /dev/systty device file, which allows remote authenticated users to read terminal data from tty0 for local users.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/45046 | vdb entry third party advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2010-December/051755.html | mailing list third party advisory vendor advisory |
http://secunia.com/advisories/42342 | third party advisory not applicable |
http://secunia.com/advisories/42451 | third party advisory not applicable |
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051418.html | mailing list third party advisory vendor advisory |
http://www.vupen.com/english/advisories/2010/3110 | vdb entry permissions required |
https://bugzilla.redhat.com/show_bug.cgi?id=654489 | issue tracking third party advisory |
http://www.vupen.com/english/advisories/2010/3062 | vdb entry permissions required |
https://bugzilla.redhat.com/show_bug.cgi?id=654935 | issue tracking third party advisory |