Bug 3799 - [UPDATE REQUEST] [UPSTREAM UPDATE] augeas
: [UPDATE REQUEST] [UPSTREAM UPDATE] augeas
Status: RESOLVED FIXED
Product: Server Bugs
Classification: ROSA Server
Component: Main Packages
: unspecified
: All Linux
: Normal normal
: ---
Assigned To: Andrew Lukoshko
: ROSA Server Bugs
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2014-02-25 16:10 MSK by Andrew Lukoshko
Modified: 2014-03-10 19:20 MSK (History)
1 user (show)

See Also:
RPM Package:
ISO-related:
Bad POT generating:
Upstream:
vladimir.potapov: qa_verified+
andrew.lukoshko: published_server+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andrew Lukoshko 2014-02-25 16:10:41 MSK
A flaw was found in the way Augeas handled certain umask settings when creating new configuration files. This flaw could result in configuration files being created as world writable, allowing unprivileged local users to modify their content. (CVE-2013-6412)

https://rhn.redhat.com/errata/RHSA-2014-0044.html

https://abf.rosalinux.ru/build_lists/1658353
https://abf.rosalinux.ru/build_lists/1658354
Comment 1 Vladimir Potapov 2014-02-26 10:53:53 MSK
augeas-1.0.0-5.res6.1
http://abf-downloads.rosalinux.ru/rosa-server65/container/1658357/
http://abf-downloads.rosalinux.ru/rosa-server65/container/1658358/
********************** Advisory ********************
A flaw was found in the way Augeas handled certain umask settings when creating new configuration files. This flaw could result in configuration files being created as world writable, allowing unprivileged local users to modify their content. (CVE-2013-6412)
****************************************************
QA Verified