VDB

GCVE-110-MAGEIA-2014-58

GCVE-110-MAGEIA-2014-58
Advisory Published
Vulnetix · Advisory published February 12, 2014
Multiple flaws were found in the way Augeas handled configuration files when updating them. An application using Augeas to update configuration files in a directory that is writable to by a different user (for example, an application running as root that is updating files in a directory owned by a non-root service user) could have been tricked into overwriting arbitrary files or leaking information via a symbolic link or mount point attack (CVE-2012-0786, CVE-2012-0787). A flaw was found in the way Augeas handled certain umask settings when creating new configuration files. This flaw could result in configuration files being created as world writable, allowing unprivileged local users to modify their content (CVE-2013-6412).

Affected Products

VendorProductVersionsPlatforms
Mageiaaugeas0 (affected), 1.1.0-1.1.mga3 (unaffected), 0 (affected), 1.1.0-1.1.mga3 (unaffected)
Mageiascilab0 (affected), 5.5.0-0.beta1.4.mga4 (unaffected)

Browse GCVE Records

74,108 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›