Dracut Project Dracut 015

CPE Details

Dracut Project Dracut 015
015
2019-07-24
10h52 +00:00
2019-07-24
10h52 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:dracut_project:dracut:015:*:*:*:*:*:*:*

Informations

Vendor

dracut_project

Product

dracut

Version

015

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2016-8637 2018-08-01 11h00 +00:00 A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio' is used, such as when including microcode updates. Local attacker can use this to obtain sensitive information from these files, such as encryption keys or credentials.
7.8
High
CVE-2015-0794 2015-11-19 19h00 +00:00 modules.d/90crypt/module-setup.sh in the dracut package before 037-17.30.1 in openSUSE 13.2 allows local users to have unspecified impact via a symlink attack on /tmp/dracut_block_uuid.map.
3.6
CVE-2012-4453 2012-10-09 21h00 +00:00 dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.
2.1