Cobbler before 2.0.4 uses an incorrect umask value, which allows local users to have an unspecified impact by leveraging world writable permissions for files and directories.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/42602 | third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=554567 | |
http://people.fedoraproject.org/~shenson/cobbler/cobbler-2.0.8.tar.gz | patch |