|
Message-Id: <20150630214059.71D3AABC0C3@smtpvmsrv1.mitre.org> Date: Tue, 30 Jun 2015 17:40:59 -0400 (EDT) From: cve-assign@...re.org To: kseifried@...hat.com Cc: cve-assign@...re.org, oss-security@...ts.openwall.com Subject: Re: Question about world readable config files and commented warnings -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 > the specific case of: > > Configuration file takes a password and has world readable permissions > by default (and let's assume no explicit warning in the comments in the > config file). CVE covers the CWE-276 ("Incorrect Default Permissions") issue and similar weak-permissions issues as long as a security boundary is crossed. A security boundary would be crossed on a general-purpose, multi-user computer, as well as on most other multi-user platforms. Typically there is an exception in the case of an embedded device where a multi-user level of access control isn't set up and wasn't ever intended or documented by the vendor. For example, obtaining an OS image of an arbitrary embedded device, and noting that it has a filesystem that supports file permissions, doesn't necessarily imply anything about what those permissions were supposed to be. - -- CVE assignment team, MITRE CVE Numbering Authority M/S M300 202 Burlington Road, Bedford, MA 01730 USA [ PGP key available through http://cve.mitre.org/cve/request_id.html ] -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.14 (SunOS) iQEcBAEBAgAGBQJVkwvZAAoJEKllVAevmvmsjSsIALdZzYAdIBfjW1UlQEfKwP7Z 7njDEjKjIHpIWOnH9S+LZyYfMBrCZT9mLtRPUzpFwNOuyV/SZBL7MBRJScyDlpQ4 INdBMNt+gN9NPbqs/ZqZgvA3LWSXSI5L8yI1DmM0Xx2/i2rZ6V6TXoH7u6+uiXDM fGA/j8M7ePyXor4dwFx0kZo8LshzE4gTx12tr1u7TIcmMzyyPCTA+LOG7MbOeBFh YICPwZPI99hGieeLmRu7+S8Cyd8pqyz4h7v1xkTheyEqFUdyp8LvuSO02uJYTeC6 8Yc/bp+QZl11OBRFDsAoIo2WBr+zASDRT60eJnvfK+v1IRmCZMqAo9fadUk8m58= =YCxq -----END PGP SIGNATURE-----
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.