Vulnerability Name: | CVE-2013-6433 (CCN-94088) | ||||||||||||||||
Assigned: | 2013-11-04 | ||||||||||||||||
Published: | 2014-06-02 | ||||||||||||||||
Updated: | 2018-10-19 | ||||||||||||||||
Summary: | The default configuration in the Red Hat openstack-neutron package before 2013.2.3-7 does not properly set a configuration file for rootwrap, which allows remote attackers to gain privileges via a crafted configuration file. | ||||||||||||||||
CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||||||
CVSS v2 Severity: | 7.6 High (CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C) 5.6 Medium (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.6 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-264 | ||||||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2013-6433 Source: REDHAT Type: Third Party Advisory RHSA-2014:0516 Source: SECUNIA Type: Third Party Advisory 59533 Source: CCN Type: Red Hat Web site openstack-neutron package Source: CCN Type: BID-67804 OpenStack Neutron Sudo Configuration Local Privilege Escalation Vulnerability Source: UBUNTU Type: Third Party Advisory USN-2255-1 Source: CCN Type: Red Hat Bugzilla Bug 1039812 CVE-2013-6433 openstack-quantum/openstack-neutron: rootwrap sudo config allows potential privilege escalation Source: CONFIRM Type: Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=1039812 Source: XF Type: UNKNOWN openstack-cve20136433-priv-esc(94088) Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-6433 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |