pulp.spec in the installation process for Pulp 2.8.3 generates the...
Vulnerability Description
pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the pulp server and pulp consumers in a directory that is world-readable before later modifying the permissions, which might allow local users to read the generated RSA keys via reading the key files while the installation process is running.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-3111
Credits & Attribution
No credits recorded in the NVD database.
References
- http://pkgs.fedoraproject.org/cgit/rpms/pulp.git/tree/pulp.spec#n620
- http://pkgs.fedoraproject.org/cgit/rpms/pulp.git/tree/pulp.spec#n317
- https://bugzilla.redhat.com/show_bug.cgi?id=1326251
- https://bugzilla.redhat.com/attachment.cgi?id=1146522
- https://access.redhat.com/errata/RHBA-2016:1501
- https://pulp.plan.io/issues/1837
- https://github.com/pulp/pulp/blob/master/pulp.spec#L894-L903
- http://www.openwall.com/lists/oss-security/2016/05/20/1
- https://github.com/pulp/pulp/blob/master/pulp.spec#L473-L486
More from pulpproject
View All →Affected Vendor
pulpproject
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.