Red Hat livecd-tools before 13.4.4, 17.x before 17.17, 18.x before 18.16, and 19.x before 19.3, when a rootpw directive is not set in a Kickstart file, sets the root user password to empty, which allows local users to gain privileges.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://aws.amazon.com/security/security-bulletins/red-hat-and-other-third-party-public-amis-security-concern/ | third party advisory |
http://www.securityfocus.com/bid/60119 | vdb entry third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/84488 | vdb entry third party advisory |
http://www.openwall.com/lists/oss-security/2013/05/23/2 | third party advisory mailing list |
https://bugzilla.redhat.com/show_bug.cgi?id=964299 | issue tracking vendor advisory |
http://rhn.redhat.com/errata/RHSA-2013-0849.html | vendor advisory |