The Gentoo init script for webfs uses world-readable permissions for /var/log/webfsd.log, which allows local users to have unspecified impact by reading the file.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://seclists.org/oss-sec/2013/q1/404 | mailing list exploit |
http://seclists.org/oss-sec/2013/q1/415 | mailing list exploit |
http://osvdb.org/90585 | vdb entry |
http://www.securityfocus.com/bid/58126 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/82356 | vdb entry |
http://seclists.org/oss-sec/2013/q1/405 | mailing list exploit |