The transform_save function in transform.c in Augeas 1.0.0 through 1.1.0 does not properly calculate the permission values when the umask contains a 7, which causes world-writable permissions to be used for new files and allows local users to modify the files via unspecified vectors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Augeas | Augeas | 1.0.0 (including) | 1.0.0 (including) |
Augeas | Augeas | 1.1.0 (including) | 1.1.0 (including) |
Augeas | Ubuntu | lucid | * |
Augeas | Ubuntu | precise | * |
Augeas | Ubuntu | raring | * |
Augeas | Ubuntu | saucy | * |
Augeas | Ubuntu | upstream | * |
Red Hat Enterprise Linux 6 | RedHat | augeas-0:1.0.0-5.el6_5.1 | * |