Fedora 'mom' PID File Insecure File Permissions Vulnerability
BID:55854
Info
Fedora 'mom' PID File Insecure File Permissions Vulnerability
| Bugtraq ID: | 55854 |
| Class: | Design Error |
| CVE: |
CVE-2012-4480 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 04 2012 12:00AM |
| Updated: | Apr 13 2015 09:49PM |
| Credit: | Florian Weimer |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Fedora 'mom' PID File Insecure File Permissions Vulnerability
Fedora mom is prone to an insecure file-permission vulnerability
A local attacker can exploit this issue to edit the PID files and terminate other processes to deny service to legitimate users. This may aid in further attacks.
Fedora mom is prone to an insecure file-permission vulnerability
A local attacker can exploit this issue to edit the PID files and terminate other processes to deny service to legitimate users. This may aid in further attacks.
Exploit / POC
Fedora 'mom' PID File Insecure File Permissions Vulnerability
Attackers can use standard, readily available tools to exploit this issue.
Attackers can use standard, readily available tools to exploit this issue.
Solution / Fix
Fedora 'mom' PID File Insecure File Permissions Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Fedora 'mom' PID File Insecure File Permissions Vulnerability
References:
References:
- Bug 863178 - CVE-2012-4480 mom: world-writable PID file [fedora-all] (Bugzilla)
- Fedora Homepage (RedHat)