CVE
- Id
- 5239
- CVE No.
- CVE-2002-0849
- Status
- Candidate
- Description
- Linux-iSCSI iSCSI implementation installs the iscsi.conf file with world-readable permissions on some operating systems, including Red Hat Linux Limbo Beta #1, which could allow local users to gain privileges by reading the cleartext CHAP password.
- Phase
- Modified (20050610)
- Votes
- MODIFY(2) Foat, Frech | NOOP(4) Armstrong, Christey, Cole, Wall | REJECT(1) Cox
- Comments
- Cox> CD:EX-BETA | Foat> The candidate notes that this vulnerability pertains to "some | operating systems" and specifically mentions only Red Hat Linux Limbo Beta #1. | We found the file to be world readable on Red Hat Linux 7.2. | Frech> XF:linux-iscsi-conf-insecure(9792) | Christey> MISC:http://www.seifried.org/security/advisories/kssa-004.html