CVE-2015-3248

Impact:
Low
Public Date:
2014-02-10
CWE:
CWE-552
Bugzilla:
1233520: CVE-2015-3248 openhpi: world writable /var/lib/openhpi directory
It was found that the "/var/lib/openhpi" directory provided by OpenHPI used world-writeable and world-readable permissions. A local user could use this flaw to view, modify, and delete OpenHPI-related data, or even fill up the storage device hosting the /var/lib directory.

Find out more about CVE-2015-3248 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

This issue affects the version of openhpi as shipped with Red Hat Enterprise Linux 5 and 6. This issue has been rated as having Low security impact and is not currently planned to be addressed in future updates of Red Hat Enterprise Linux 5 and 6.

CVSS v2 metrics

Base Score 4.6
Base Metrics AV:L/AC:L/Au:N/C:P/I:P/A:P
Access Vector Local
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 7 (openhpi) RHSA-2015:2369 2015-11-19

Affected Packages State

Platform Package State
Red Hat Enterprise Linux 6 openhpi Will not fix
Red Hat Enterprise Linux 5 openhpi Will not fix

Acknowledgements

This issue was discovered by Marko Myllynen of Red Hat.

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.