CVE-2017-15131
published 2018-01-09CVE-2017-15131: It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask…
PriorityP335high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.32%
24.5th percentile
It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy. This only affects xdg-user-dirs before 0.15.5 as shipped with Red Hat Enterprise Linux.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xdg-user-dirs | — | — |
| freedesktop | xdg-user-dirs | < 0.15.5 | 0.15.5 |
| red_hat_inc | rhel_shipped_xdg-user-dirs_and_gnome-session | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q4r5-4gjj-jww9: It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs
ghsa_unreviewed·2022-05-13
CVE-2017-15131 [HIGH] CWE-276 GHSA-q4r5-4gjj-jww9: It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs
It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy. This only affects xdg-user-dirs before 0.15.5 as shipped with Red Hat Enterprise Linux.
OSV
CVE-2017-15131: It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs
osv·2018-01-09·CVSS 7.8
CVE-2017-15131 [HIGH] CVE-2017-15131: It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs
It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy. This only affects xdg-user-dirs before 0.15.5 as shipped with Red Hat Enterprise Linux.
Red Hat
gnome-session: Xsession creation of XDG user directories does not honor system umask policy
vendor_redhat·2017-01-12·CVSS 7.8
CVE-2017-15131 [HIGH] CWE-266 gnome-session: Xsession creation of XDG user directories does not honor system umask policy
gnome-session: Xsession creation of XDG user directories does not honor system umask policy
It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy. This only affects xdg-user-dirs before 0.15.5 as shipped with Red Hat Enterprise Linux.
It was found that the system umask policy is not being honored when creating XDG user directories (~/Desktop etc) on first login. This could lead to user's files being inadvertently exposed to other local users.
Package: xdg-user-dirs (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2017-15131: xdg-user-dirs - It was found that system umask policy is not being honored when creating XDG use...
vendor_debian·2017·CVSS 7.8
CVE-2017-15131 [HIGH] CVE-2017-15131: xdg-user-dirs - It was found that system umask policy is not being honored when creating XDG use...
It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy. This only affects xdg-user-dirs before 0.15.5 as shipped with Red Hat Enterprise Linux.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-15131 gnome-session: xdg-user-dirs, gnome-session: Xsession creation of XDG user directories does not honor system umask policy [fedora-all]
bugzilla·2017-05-24·CVSS 7.8
CVE-2017-15131 [HIGH] CVE-2017-15131 gnome-session: xdg-user-dirs, gnome-session: Xsession creation of XDG user directories does not honor system umask policy [fedora-all]
CVE-2017-15131 gnome-session: xdg-user-dirs, gnome-session: Xsession creation of XDG user directories does not honor system umask policy [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedp
Bugzilla
CVE-2017-15131 xdg-user-dirs, gnome-session: Xsession creation of XDG user directories does not honor system umask policy
bugzilla·2017-05-24·CVSS 7.8
CVE-2017-15131 [HIGH] CVE-2017-15131 xdg-user-dirs, gnome-session: Xsession creation of XDG user directories does not honor system umask policy
CVE-2017-15131 xdg-user-dirs, gnome-session: Xsession creation of XDG user directories does not honor system umask policy
It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy.
Product bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1412762
Discussion:
Created gnome-session tracking bugs for this issue:
Affects: fedora-all [bug 1455095]
Created xdg-user-dirs tracking bugs for this issue:
Affects: fedora-all [bug 1455096]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:0842 https://access.redhat.com/errata/RHSA-2018:0842
Bugzilla
CVE-2017-15131 xdg-user-dirs: xdg-user-dirs, gnome-session: Xsession creation of XDG user directories does not honor system umask policy [fedora-all]
bugzilla·2017-05-24·CVSS 7.8
CVE-2017-15131 [HIGH] CVE-2017-15131 xdg-user-dirs: xdg-user-dirs, gnome-session: Xsession creation of XDG user directories does not honor system umask policy [fedora-all]
CVE-2017-15131 xdg-user-dirs: xdg-user-dirs, gnome-session: Xsession creation of XDG user directories does not honor system umask policy [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedp
https://access.redhat.com/errata/RHSA-2018:0842https://bugzilla.redhat.com/show_bug.cgi?id=1412762https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3Ehttps://access.redhat.com/errata/RHSA-2018:0842https://bugzilla.redhat.com/show_bug.cgi?id=1412762https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E
2018-01-09
Published