CVE-2013-4367
published 2019-11-01CVE-2013-4367: ovirt-engine 3.2 running on Linux kernel 3.1 and newer creates certain files world-writeable due to an upstream kernel change which impacted how python's…
PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.32%
24.3th percentile
ovirt-engine 3.2 running on Linux kernel 3.1 and newer creates certain files world-writeable due to an upstream kernel change which impacted how python's os.chmod() works when passed a mode of '-1'.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ovirt-engine | ovirt-engine | — | — |
| ovirt | ovirt-engine | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ovirt-engine: some config files left world-writable due to improper use of os.chmod()
vendor_redhat·2013-09-23·CVSS 7.8
CVE-2013-4367 [HIGH] ovirt-engine: some config files left world-writable due to improper use of os.chmod()
ovirt-engine: some config files left world-writable due to improper use of os.chmod()
ovirt-engine 3.2 running on Linux kernel 3.1 and newer creates certain files world-writeable due to an upstream kernel change which impacted how python's os.chmod() works when passed a mode of '-1'.
Statement: Not vulnerable. This issue did not affect Red Hat Enterprise Virtualization Manager 3.
GHSA
GHSA-7rjr-g954-m9f4: ovirt-engine 3
ghsa_unreviewed·2022-05-05
CVE-2013-4367 [MEDIUM] GHSA-7rjr-g954-m9f4: ovirt-engine 3
ovirt-engine 3.2 running on Linux kernel 3.1 and newer creates certain files world-writeable due to an upstream kernel change which impacted how python's os.chmod() works when passed a mode of '-1'.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4367 ovirt-engine: some config files left world-writable due to improper use of os.chmod()
bugzilla·2013-09-24·CVSS 7.8
CVE-2013-4367 [HIGH] CVE-2013-4367 ovirt-engine: some config files left world-writable due to improper use of os.chmod()
CVE-2013-4367 ovirt-engine: some config files left world-writable due to improper use of os.chmod()
It was found that ovirt-engine would create certain files world-writable (such as /etc/sysconfig/nfs). This is due to an upstream kernel change [1] which impacts how python's os.chmod() works when passed a mode of '-1'. Prior to this kernel change, a mode of '-1' would have implied "do nothing", however with the upstream kernel change this will turn all possible bits on (thus making the file world-writable).
As a result, this only affects ovirt-engine (or other python scripts using os.chmod() in this way) with newer Linux kernels (version 3.1 and newer).
This has been in upstream git [2] to fix permissions on installations that upgrade from 3.2. In 3.3, the entire setup package was rewrit
Bugzilla
CVE-2013-4367 ovirt-engine: some config files left world-writable due to improper use of os.chmod() [fedora-all]
bugzilla·2013-09-24·CVSS 7.8
CVE-2013-4367 [HIGH] CVE-2013-4367 ovirt-engine: some config files left world-writable due to improper use of os.chmod() [fedora-all]
CVE-2013-4367 ovirt-engine: some config files left world-writable due to improper use of os.chmod() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when avai
2019-11-01
Published