redis: world-readable ~/.rediscli_history
Published Aug 10, 2016
3.3
LOWCVSS 3.0
EPSS 0.48%
Description
linenoise, as used in Redis before 3.2.3, uses world-readable permissions for .rediscli_history, which allows local users to obtain sensitive information by reading the file.
Affected products
No data.
Configuration 2
- 8.0
No data.
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)
redis
Will not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)
redis
Will not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational Tools
redis
Will not fix
Red Hat OpenStack Platform 10 (Newton)
redis
Will not fix
Red Hat OpenStack Platform 8 (Liberty)
redis
Will not fix
Red Hat OpenStack Platform 8 (Liberty) Operational Tools
redis
Will not fix
Red Hat OpenStack Platform 9 (Mitaka)
redis
Will not fix
Red Hat OpenStack Platform 9 (Mitaka) Operational Tools
redis
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) | redis | Will not fix | n/a |
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | redis | Will not fix | n/a |
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational Tools | redis | Will not fix | n/a |
| Red Hat OpenStack Platform 10 (Newton) | redis | Will not fix | n/a |
| Red Hat OpenStack Platform 8 (Liberty) | redis | Will not fix | n/a |
| Red Hat OpenStack Platform 8 (Liberty) Operational Tools | redis | Will not fix | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) | redis | Will not fix | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) Operational Tools | redis | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security has rated this issue as having security impact of Low. Further, home directories are not world readable on RHEL distributions (by default). This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
References (14)
- http://lists.opensuse.org/opensuse-updates/2016-08/msg00029.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-08/msg00030.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://www.debian.org/security/2016/dsa-3634 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2013-7458 Vendor Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=832460 x_refsource_CONFIRMMailing ListThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1363670 Issue Tracking
- https://github.com/antirez/linenoise/issues/121 x_refsource_CONFIRMPatchThird Party Advisory
- https://github.com/antirez/linenoise/pull/122 x_refsource_CONFIRMPatchThird Party Advisory
- https://github.com/antirez/redis/blob/3.2/00-RELEASENOTES x_refsource_CONFIRMRelease Notes
- https://github.com/antirez/redis/issues/3284 x_refsource_CONFIRMPatchThird Party Advisory
- https://github.com/antirez/redis/pull/1418 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://github.com/antirez/redis/pull/3322 x_refsource_CONFIRMPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-7458
- https://www.cve.org/CVERecord?id=CVE-2013-7458
Change history (0)
No recorded changes yet.