CVE-2010-2241 Information

Description

The (1) setup-ds.pl and (2) setup-ds-admin.pl setup scripts for Red Hat Directory Server 8 before 8.2 use world-readable permissions when creating cache files which allows local users to obtain sensitive information including passwords for Directory and Administration Server administrative accounts.

Reference

http://rhn.redhat.com/errata/RHSA-2010-0590.html http://secunia.com/advisories/40811 http://www.osvdb.org/66962 http://www.securitytracker.com/id?1024281 https://bugzilla.redhat.com/show_bug.cgi?id=608032

Share on: