Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-Id: <20150630214059.71D3AABC0C3@smtpvmsrv1.mitre.org>
Date: Tue, 30 Jun 2015 17:40:59 -0400 (EDT)
From: cve-assign@...re.org
To: kseifried@...hat.com
Cc: cve-assign@...re.org, oss-security@...ts.openwall.com
Subject: Re: Question about world readable config files and commented warnings

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

> the specific case of:
> 
> Configuration file takes a password and has world readable permissions
> by default (and let's assume no explicit warning in the comments in the
> config file).

CVE covers the CWE-276 ("Incorrect Default Permissions") issue and
similar weak-permissions issues as long as a security boundary is
crossed. A security boundary would be crossed on a general-purpose,
multi-user computer, as well as on most other multi-user platforms.
Typically there is an exception in the case of an embedded device
where a multi-user level of access control isn't set up and wasn't
ever intended or documented by the vendor. For example, obtaining an
OS image of an arbitrary embedded device, and noting that it has a
filesystem that supports file permissions, doesn't necessarily imply
anything about what those permissions were supposed to be.

- -- 
CVE assignment team, MITRE CVE Numbering Authority
M/S M300
202 Burlington Road, Bedford, MA 01730 USA
[ PGP key available through http://cve.mitre.org/cve/request_id.html ]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (SunOS)

iQEcBAEBAgAGBQJVkwvZAAoJEKllVAevmvmsjSsIALdZzYAdIBfjW1UlQEfKwP7Z
7njDEjKjIHpIWOnH9S+LZyYfMBrCZT9mLtRPUzpFwNOuyV/SZBL7MBRJScyDlpQ4
INdBMNt+gN9NPbqs/ZqZgvA3LWSXSI5L8yI1DmM0Xx2/i2rZ6V6TXoH7u6+uiXDM
fGA/j8M7ePyXor4dwFx0kZo8LshzE4gTx12tr1u7TIcmMzyyPCTA+LOG7MbOeBFh
YICPwZPI99hGieeLmRu7+S8Cyd8pqyz4h7v1xkTheyEqFUdyp8LvuSO02uJYTeC6
8Yc/bp+QZl11OBRFDsAoIo2WBr+zASDRT60eJnvfK+v1IRmCZMqAo9fadUk8m58=
=YCxq
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.