HIGH
openstack-quantum/openstack-neutron: rootwrap sudo config allows potential privilege escalation
Published Jun 2, 2014
7.6
HIGHCVSS 2.0
EPSS 3.32%
Description
The default configuration in the Red Hat openstack-neutron package before 2013.2.3-7 does not properly set a configuration file for rootwrap, which allows remote attackers to gain privileges via a crafted configuration file.
Affected products
No data.
Configuration 2
OR
- 13.10
- 14.04
No data.
OpenStack 4 for RHEL 6
openstack-neutron-0:2013.2.3-7.el6ost
Fixed · RHSA-2014:0516
Red Hat OpenStack Platform 3
openstack-quantum
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenStack 4 for RHEL 6 | openstack-neutron-0:2013.2.3-7.el6ost | Fixed | RHSA-2014:0516 |
| Red Hat OpenStack Platform 3 | openstack-quantum | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- http://rhn.redhat.com/errata/RHSA-2014-0516.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://secunia.com/advisories/59533 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://www.ubuntu.com/usn/USN-2255-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2013-6433 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1039812 x_refsource_CONFIRMThird Party AdvisoryIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2013-6433
- https://www.cve.org/CVERecord?id=CVE-2013-6433
| Link | Providers | Tags |
|---|---|---|
| http://rhn.redhat.com/errata/RHSA-2014-0516.html | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| http://secunia.com/advisories/59533 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://www.ubuntu.com/usn/USN-2255-1 | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2013-6433 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1039812 | x_refsource_CONFIRMThird Party AdvisoryIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2013-6433 | ||
| https://www.cve.org/CVERecord?id=CVE-2013-6433 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 2, 2014
Updated Aug 6, 2024
Reserved Nov 4, 2013
Link CVE-2013-6433
CISA Vulnrichment
Updated n/a