dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.
During installation, installed file permissions are set to allow anyone to modify those files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dracut | Dracut_project | * | 024 (excluding) |
Red Hat Enterprise Linux 6 | RedHat | dracut-0:004-336.el6 | * |
Dracut | Ubuntu | natty | * |
Dracut | Ubuntu | oneiric | * |
Dracut | Ubuntu | precise | * |
Dracut | Ubuntu | quantal | * |
Dracut | Ubuntu | raring | * |
Dracut | Ubuntu | saucy | * |
Dracut | Ubuntu | upstream | * |
Dracut | Ubuntu | utopic | * |
Dracut | Ubuntu | vivid | * |
Dracut | Ubuntu | wily | * |