The cgrulesengd daemon (cgred) in libcgroup through version 0.41 creates log files (/var/log/cgred) with world readable and writable permissions (0o666) due to a reset of the file mode creation mask (umask(0)) in the daemon/cgrulesengd.c:cgre_start_daemon() function (CVE-2018-14348). . MGASA-2018-0380 - Updated libcgroup packages fix security vulnerability Publication date: 21 Sep 2018 URL: https://advisories.mageia.org/MGASA-2018-0380.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-14348 The cgrulesengd daemon (cgred) in libcgroup through version 0.41 creates log files (/var/log/cgred) with world readable and writable permissions (0o666) due to a reset of the file mode creation mask (umask(0)) in the daemon/cgrulesengd.c:cgre_start_daemon() function (CVE-2018-14348). References: - https://bugs.mageia.org/show_bug.cgi?id=23380 - https://lists.fedoraproject.org/archives/list/
Get the latest Linux and open source security news straight to your inbox.