CVE-2013-4481
published 2013-11-23CVE-2013-4481: Race condition in Luci 0.26.0 creates /var/lib/luci/etc/luci.ini with world-readable permissions before restricting the permissions, which allows local users…
PriorityP44low1.9CVSS 2.0
AVLACMAuNCPINAN
EPSS
0.25%
16.2th percentile
Race condition in Luci 0.26.0 creates /var/lib/luci/etc/luci.ini with world-readable permissions before restricting the permissions, which allows local users to read the file and obtain sensitive information such as "authentication secrets."
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux | — | — |
| scientificlinux | luci | — | — |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ffhg-m72p-75j9: Race condition in Luci 0
ghsa_unreviewed·2022-05-14
CVE-2013-4481 [LOW] CWE-362 GHSA-ffhg-m72p-75j9: Race condition in Luci 0
Race condition in Luci 0.26.0 creates /var/lib/luci/etc/luci.ini with world-readable permissions before restricting the permissions, which allows local users to read the file and obtain sensitive information such as "authentication secrets."
Red Hat
luci: short exposure of authentication secrets while generating configuration file
vendor_redhat·2013-11-20·CVSS 1.9
CVE-2013-4481 [LOW] luci: short exposure of authentication secrets while generating configuration file
luci: short exposure of authentication secrets while generating configuration file
Race condition in Luci 0.26.0 creates /var/lib/luci/etc/luci.ini with world-readable permissions before restricting the permissions, which allows local users to read the file and obtain sensitive information such as "authentication secrets."
A flaw was found in the way luci generated its configuration file. The file was created as world readable for a short period of time, allowing a local user to gain access to the authentication secrets stored in the configuration file.
No detection rules found.
No public exploits indexed.
2013-11-23
Published