CVE-2016-8637 Information
Feb 14, 2021
cve
Description
A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when ’early cpio’ is used such as when including microcode updates. Local attacker can use this to obtain sensitive information from these files such as encryption keys or credentials.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
http://seclists.org/oss-sec/2016/q4/352 http://www.securityfocus.com/bid/94128 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8637 https://github.com/dracutdevs/dracut/commit/0db98910a11c12a454eac4c8e86dc7a7bbc764a4
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: