← Back to CVE List
Vulnerability Intelligence Report

CVE-2013-6412

The transform_save function in transform.c in Augeas 1.0.0 through 1.1.0 does not properly calculate the permission values when the umask contains a "7," which causes world-writable permissions to be used for new files and allows local users to modify the files via unspecified vectors.

No Active Exploit Signals
CVSS Base Score
4.6
MEDIUM
EPSS Probability:0.37%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
augeas augeas 1.0.0, 1.1.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.368%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityRed Hat, Inc. · Vendor · USA
Reserved2013-11-04T00:00:00
Published2014-01-23T00:00:00
Patch Date2014-01-20
Last Updated2024-08-06T17:39:01

LINK COPIED TO CLIPBOARD