CVE-2012-4453
published 2012-10-09CVE-2012-4453: dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable…
PriorityP44low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.36%
28.7th percentile
dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dracut | < dracut 020-1.1 (bookworm) | dracut 020-1.1 (bookworm) |
| dracut_project | dracut | < 024 | 024 |
| dracut_project | dracut | >= 0 < 020-1.1 | 020-1.1 |
| dracut_project | dracut | >= 0 < 020-1.1 | 020-1.1 |
| dracut_project | dracut | >= 0 < 020-1.1 | 020-1.1 |
| dracut_project | dracut | >= 0 < 020-1.1 | 020-1.1 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-84vh-967q-qr87: dracut
ghsa_unreviewed·2022-05-13
CVE-2012-4453 [LOW] CWE-276 GHSA-84vh-967q-qr87: dracut
dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.
OSV
CVE-2012-4453: dracut
osv·2012-10-09·CVSS 2.1
CVE-2012-4453 [LOW] CVE-2012-4453: dracut
dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.
Red Hat
dracut: Creates initramfs images with world-readable permissions (information disclosure)
vendor_redhat·2012-09-27·CVSS 2.1
CVE-2012-4453 [LOW] dracut: Creates initramfs images with world-readable permissions (information disclosure)
dracut: Creates initramfs images with world-readable permissions (information disclosure)
dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.
It was discovered that dracut created initramfs images as world readable. A local user could possibly use this flaw to obtain sensitive information from these files, such as iSCSI authentication passwords, encrypted root file system crypttab passwords, or other information.
Debian
CVE-2012-4453: dracut - dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, an...
vendor_debian·2012·CVSS 2.1
CVE-2012-4453 [LOW] CVE-2012-4453: dracut - dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, an...
dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.
Scope: local
bookworm: resolved (fixed in 020-1.1)
bullseye: resolved (fixed in 020-1.1)
forky: resolved (fixed in 020-1.1)
sid: resolved (fixed in 020-1.1)
trixie: resolved (fixed in 020-1.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-13179 calamares: incorrect permission leads to disclosure of decryption keys for LUKS container
bugzilla·2019-07-03·CVSS 2.1
CVE-2019-13179 [LOW] CVE-2019-13179 calamares: incorrect permission leads to disclosure of decryption keys for LUKS container
CVE-2019-13179 calamares: incorrect permission leads to disclosure of decryption keys for LUKS container
Calamares through 3.2.4 copies a LUKS encryption keyfile from /crypto_keyfile.bin (mode 0600 owned by root) to /boot within a globally readable initramfs image with insecure permissions, which allows this originally protected file to be read by any user, thereby disclosing decryption keys for LUKS containers created with Full Disk Encryption.
Reference:
https://github.com/calamares/calamares/issues/1191
Discussion:
Created calamares tracking bugs for this issue:
Affects: fedora-all [bug 1726543]
---
This CVE only affects the Debian mkinitramfs (initramfs-tools), which is not used in the Fedora configuration for Calamares. The underlying tool is also not shipped at all by Fedora.
Bugzilla
CVE-2019-13179 calamares: incorrect permission leads to disclosure of decryption keys for LUKS container [fedora-all]
bugzilla·2019-07-03·CVSS 7.5
CVE-2019-13179 [HIGH] CVE-2019-13179 calamares: incorrect permission leads to disclosure of decryption keys for LUKS container [fedora-all]
CVE-2019-13179 calamares: incorrect permission leads to disclosure of decryption keys for LUKS container [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this i
Bugzilla
CVE-2012-4453 dracut: Creates initramfs images with world-readable permissions (information disclosure) [fedora-all]
bugzilla·2012-09-27·CVSS 2.1
CVE-2012-4453 [LOW] CVE-2012-4453 dracut: Creates initramfs images with world-readable permissions (information disclosure) [fedora-all]
CVE-2012-4453 dracut: Creates initramfs images with world-readable permissions (information disclosure) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedo
Bugzilla
CVE-2012-4453 dracut: Creates initramfs images with world-readable permissions (information disclosure)
bugzilla·2012-09-21·CVSS 2.1
CVE-2012-4453 [LOW] CVE-2012-4453 dracut: Creates initramfs images with world-readable permissions (information disclosure)
CVE-2012-4453 dracut: Creates initramfs images with world-readable permissions (information disclosure)
An information disclosure flaw was found in the way dracut, an initramfs root filesystem images generator, created initramfs images. When the root filesystem contained sensitive information (password based authentication for iSCSI systems or encrypted root filesystem crypttab password information), an attacker could use this flaw to obtain this information.
Acknowledgements:
This issue was discovered by Peter Jones of the Red Hat Installer Team.
Discussion:
This issue affects the version of the dracut package, as shipped with Red Hat Enterprise Linux 6.
--
This issue affects the versions of the dracut package, as shipped with Fedora release of 16 and 17.
---
Created attachment 6
http://git.kernel.org/?p=boot/dracut/dracut.git%3Ba=commit%3Bh=e1b48995c26c4f06d1a71http://rhn.redhat.com/errata/RHSA-2013-1674.htmlhttp://www.openwall.com/lists/oss-security/2012/09/27/3http://www.openwall.com/lists/oss-security/2012/09/27/4http://www.openwall.com/lists/oss-security/2012/09/27/6http://www.securityfocus.com/bid/55713https://bugzilla.redhat.com/show_bug.cgi?id=859448https://exchange.xforce.ibmcloud.com/vulnerabilities/79258http://git.kernel.org/?p=boot/dracut/dracut.git%3Ba=commit%3Bh=e1b48995c26c4f06d1a71http://rhn.redhat.com/errata/RHSA-2013-1674.htmlhttp://www.openwall.com/lists/oss-security/2012/09/27/3http://www.openwall.com/lists/oss-security/2012/09/27/4http://www.openwall.com/lists/oss-security/2012/09/27/6http://www.securityfocus.com/bid/55713https://bugzilla.redhat.com/show_bug.cgi?id=859448https://exchange.xforce.ibmcloud.com/vulnerabilities/79258
2012-10-09
Published