openhpi/Makefile.am in OpenHPI before 3.6.0 uses world-writable permissions for /var/lib/openhpi directory, which allows local users, when quotas are not properly setup, to fill the filesystem hosting /var/lib and cause a denial of service (disk consumption).
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
http://openhpi.org/Changelogs/3.6.0 | release notes vendor advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168841.html | third party advisory vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1233521 | issue tracking vdb entry third party advisory |