Lucene search

K
cve[email protected]CVE-2013-4481
HistoryNov 23, 2013 - 11:55 a.m.

CVE-2013-4481

2013-11-2311:55:04
CWE-362
web.nvd.nist.gov
28
cve-2013-4481
luci
race condition
permissions
local users
sensitive information
nvd

1.9 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

5.6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

Race condition in Luci 0.26.0 creates /var/lib/luci/etc/luci.ini with world-readable permissions before restricting the permissions, which allows local users to read the file and obtain sensitive information such as “authentication secrets.”

Affected configurations

NVD
Node
scientificlinuxluciMatch0.26.0
OR
redhatenterprise_linuxMatch6.0

1.9 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

5.6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%