Red Hat Network (RHN) Configuration Client (rhncfg-client) in rhncfg before 5.10.27-8 uses weak permissions (world-readable) for /var/log/rhncfg-actions, which allows local users to obtain sensitive information about the rhncfg-client actions by reading the file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Rhncfg | Redhat | * | 5.10.27 (including) |
Red Hat Network Tools for RHEL 5 | RedHat | rhncfg-0:5.10.27-8.el5sat | * |
Red Hat Network Tools for RHEL 5.3.LL | RedHat | rhncfg-0:5.10.27-8.el5sat | * |
Red Hat Network Tools for RHEL 5.6.Z | RedHat | rhncfg-0:5.10.27-8.el5sat | * |
Red Hat Network Tools for RHEL 6 | RedHat | rhncfg-0:5.10.27-8.el6sat | * |
Red Hat Network Tools for RHEL 6.0.Z | RedHat | rhncfg-0:5.10.27-8.el6sat | * |
Red Hat Network Tools for RHEL 6.1.Z | RedHat | rhncfg-0:5.10.27-8.el6sat | * |
Red Hat Network Tools for RHEL 6.2.Z | RedHat | rhncfg-0:5.10.27-8.el6sat | * |
Red Hat Network Tools for RHEL 6.3.Z | RedHat | rhncfg-0:5.10.27-8.el6sat | * |