CVE-2018-14348Sensitive Information Exposure in Libcgroup

Severity
8.1HIGHNVD
EPSS
0.5%
top 33.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 14
Latest updateMay 14

Description

libcgroup up to and including 0.41 creates /var/log/cgred with mode 0666 regardless of the configured umask, leading to disclosure of information.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages9 packages

Also affects: Debian Linux 8.0, Fedora 28

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pp2m-446r-52q7: libcgroup up to and including 02022-05-14
OSV
CVE-2018-14348: libcgroup up to and including 02018-08-14

📋Vendor Advisories

4
Ubuntu
libcgroup vulnerability2021-03-15
Microsoft
libcgroup up to and including 0.41 creates /var/log/cgred with mode 0666 regardless of the configured umask leading to disclosure of information.2018-08-14
Red Hat
libcgroup: cgrulesengd creates log files with insecure permissions2018-07-25
Debian
CVE-2018-14348: libcgroup - libcgroup up to and including 0.41 creates /var/log/cgred with mode 0666 regardl...2018

💬Community

2
Bugzilla
CVE-2018-14348 libcgroup: cgrulesengd creates log files with insecure permissions2018-08-02
Bugzilla
CVE-2018-14348 libcgroup: cgrulesengd creates log files with insecure permissions [fedora-all]2018-08-02