Back

HIGH

keepalived: Insecure use of temporary files allows attackers read sensitive information from pre-existing files

Published Nov 8, 2018

Description

keepalived 2.0.8 didn't check for existing plain files when writing data to a temporary file upon a call to PrintData or PrintStats. If a local attacker had previously created a file with the expected name (e.g., /tmp/keepalived.data or /tmp/keepalived.stats), with read access for the attacker and write access for the keepalived process, then this potentially leaked sensitive information.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of keepalived as shipped with Red Hat Enterprise Linux 6 and 7 as the packages are not built with dbus support, therefore the vulnerable code is not available in resulting RPM and the issue cannot be exploited.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 8, 2018
Updated Aug 5, 2024
Reserved Nov 6, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Nov 8, 2018