Dracut Project Dracut vulnerabilities
3 known vulnerabilities affecting dracut_project/dracut.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1LOW2
Vulnerabilities
Page 1 of 1
CVE-2016-8637HIGHCVSS 7.8fixed in 0452018-08-01
CVE-2016-8637 [HIGH] CWE-732 CVE-2016-8637: A local information disclosure issue was found in dracut before 045 when generating initramfs images
A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio' is used, such as when including microcode updates. Local attacker can use this to obtain sensitive information from these files, such as encryption keys or credentials.
nvdosv
CVE-2015-0794LOWCVSS 3.6fixed in 037-17.30.12015-11-19
CVE-2015-0794 [LOW] CWE-59 CVE-2015-0794: modules.d/90crypt/module-setup.sh in the dracut package before 037-17.30.1 in openSUSE 13.2 allows l
modules.d/90crypt/module-setup.sh in the dracut package before 037-17.30.1 in openSUSE 13.2 allows local users to have unspecified impact via a symlink attack on /tmp/dracut_block_uuid.map.
nvd
CVE-2012-4453LOWCVSS 2.1fixed in 0242012-10-09
CVE-2012-4453 [LOW] CWE-276 CVE-2012-4453: dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other pro
dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.
nvdosv