tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://security-tracker.debian.org/tracker/CVE-2012-6136 | third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-6136 | third party advisory issue tracking |