Lucene search

K
prionPRIOn knowledge basePRION:CVE-2018-19046
HistoryNov 08, 2018 - 8:29 p.m.

Information disclosure

2018-11-0820:29:00
PRIOn knowledge base
www.prio-n.com
5

5.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

keepalived 2.0.8 didn’t check for existing plain files when writing data to a temporary file upon a call to PrintData or PrintStats. If a local attacker had previously created a file with the expected name (e.g., /tmp/keepalived.data or /tmp/keepalived.stats), with read access for the attacker and write access for the keepalived process, then this potentially leaked sensitive information.

CPENameOperatorVersion
keepalivedeq2.0.8

5.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%