Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <2165372.NOAPVG722M@rem0te-expl0it>
Date: Fri, 22 May 2015 00:36:36 +0530
From: Siddharth Sharma <sisharma@...hat.com>
To: oss-security@...ts.openwall.com
Cc: cve-assign@...re.org
Subject: CVE Request for ceph-deploy copying keyring to /etc/ceph which is world readable

Hi,

"ceph-deploy admin" command pushes the client.admin key with world readable 
permissions as in /etc/ceph/ceph.client.admin.keyring, It is similar issue 
like CVE-2015-3010 , but this seems more bad as it is copying to /etc/ceph 
which readable by any user. 

~]# ls -Z /etc/ | grep ceph
drwxr-xr-x. root root system_u:object_r:etc_t:s0 ceph

For further informataion : http://tracker.ceph.com/issues/11694


-- 
Siddharth Sharma / Red Hat Product Security / Key ID : 0xD9F6489A      
Fingerprint :  0x6F04C684 A49C E4CE 8148 E841 CD6F 8E55 D9F6 489A

Download attachment "signature.asc" of type "application/pgp-signature" (820 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.