« List of all CVEs

CVE-2013-6412

Published: 1/23/2014 Last updated: 8/6/2024 Reserved: 11/4/2013

The transform_save function in transform.c in Augeas 1.0.0 through 1.1.0 does not properly calculate the permission values when the umask contains a "7," which causes world-writable permissions to be used for new files and allows local users to modify the files via unspecified vectors.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Opam packages affected (1)

augeas

Products affected (1)

Product Vendor Version
n/a n/a n/a

References (8)