An information disclosure vulnerability exists in the way Azure WaLinuxAgent creates swap files on resource disks, aka 'Azure Linux Agent Information Disclosure Vulnerability'.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0804 | patch vendor advisory mitigation |
https://access.redhat.com/errata/RHSA-2019:1527 | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00037.html | vendor advisory |