Freenet6 Client Default Installation Configuration File Permission Vulnerability
BID:11280
Info
Freenet6 Client Default Installation Configuration File Permission Vulnerability
| Bugtraq ID: | 11280 |
| Class: | Configuration Error |
| CVE: |
CVE-2004-0563 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 30 2004 12:00AM |
| Updated: | Jul 12 2009 07:06AM |
| Credit: | The discovery of this issue is credited to Simon Josefsson. |
| Vulnerable: |
Freenet6 Freenet6 1.0 Freenet6 Freenet6 0.9.6 |
| Not Vulnerable: | |
Discussion
Freenet6 Client Default Installation Configuration File Permission Vulnerability
Freenet6 is affected by a default install configuration file permission vulnerability. This issue is due to a default configuration error..
An attacker may leverage this issue to steal authentication information from the configuration file that is by default set as world readable.
Freenet6 is affected by a default install configuration file permission vulnerability. This issue is due to a default configuration error..
An attacker may leverage this issue to steal authentication information from the configuration file that is by default set as world readable.
Exploit / POC
Freenet6 Client Default Installation Configuration File Permission Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Freenet6 Client Default Installation Configuration File Permission Vulnerability
Solution:
Debian has released an advisory (DSA 555-1) along with fixes dealing with this issue. Please see the referenced advisory for more information.
Freenet6 Freenet6 0.9.6
Solution:
Debian has released an advisory (DSA 555-1) along with fixes dealing with this issue. Please see the referenced advisory for more information.
Freenet6 Freenet6 0.9.6
-
Debian freenet6_0.9.6-1woody2_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/freenet6/freenet6_0.9.6 -1woody2_alpha.deb -
Debian freenet6_0.9.6-1woody2_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/freenet6/freenet6_0.9.6 -1woody2_arm.deb -
Debian freenet6_0.9.6-1woody2_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/freenet6/freenet6_0.9.6 -1woody2_hppa.deb -
Debian freenet6_0.9.6-1woody2_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/freenet6/freenet6_0.9.6 -1woody2_i386.deb -
Debian freenet6_0.9.6-1woody2_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/freenet6/freenet6_0.9.6 -1woody2_ia64.deb -
Debian freenet6_0.9.6-1woody2_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/freenet6/freenet6_0.9.6 -1woody2_m68k.deb -
Debian freenet6_0.9.6-1woody2_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/freenet6/freenet6_0.9.6 -1woody2_mips.deb -
Debian freenet6_0.9.6-1woody2_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/freenet6/freenet6_0.9.6 -1woody2_mipsel.deb -
Debian freenet6_0.9.6-1woody2_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/freenet6/freenet6_0.9.6 -1woody2_powerpc.deb -
Debian freenet6_0.9.6-1woody2_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/freenet6/freenet6_0.9.6 -1woody2_s390.deb -
Debian freenet6_0.9.6-1woody2_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/freenet6/freenet6_0.9.6 -1woody2_sparc.deb
References
Freenet6 Client Default Installation Configuration File Permission Vulnerability
References:
References:
- Debian Freenet6 Package Page (Debian)