The Subscription Manager package (aka subscription-manager) before 1.17.7-1 for Candlepin uses weak permissions (755) for subscription-manager cache directories, which allows local users to obtain sensitive information by reading files in the directories.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Enterprise_linux_desktop | Redhat | 6.0 (including) | 6.0 (including) |
Enterprise_linux_desktop | Redhat | 7.0 (including) | 7.0 (including) |
Enterprise_linux_hpc_node | Redhat | 6.0 (including) | 6.0 (including) |
Enterprise_linux_hpc_node | Redhat | 7.0 (including) | 7.0 (including) |
Enterprise_linux_server | Redhat | 6.0 (including) | 6.0 (including) |
Enterprise_linux_server | Redhat | 7.0 (including) | 7.0 (including) |
Enterprise_linux_workstation | Redhat | 6.0 (including) | 6.0 (including) |
Enterprise_linux_workstation | Redhat | 7.0 (including) | 7.0 (including) |
Red Hat Enterprise Linux 6 | RedHat | python-rhsm-0:1.18.6-1.el6 | * |
Red Hat Enterprise Linux 6 | RedHat | subscription-manager-0:1.18.10-1.el6 | * |
Red Hat Enterprise Linux 6 | RedHat | subscription-manager-migration-data-0:2.0.34-1.el6 | * |
Red Hat Enterprise Linux 7 | RedHat | python-rhsm-0:1.17.9-1.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | subscription-manager-0:1.17.15-1.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | subscription-manager-migration-data-0:2.0.31-1.el7 | * |