[Bug 991250] New: VUL-0: CVE-2013-7458: redis: World readable .rediscli_history
http://bugzilla.suse.com/show_bug.cgi?id=991250 Bug ID: 991250 Summary: VUL-0: CVE-2013-7458: redis: World readable .rediscli_history Classification: openSUSE Product: openSUSE Distribution Version: Leap 42.1 Hardware: Other OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security Assignee: security-team@suse.de Reporter: astieger@suse.com QA Contact: qa-bugs@suse.de CC: kstreitova@suse.com, lars.vogdt@microfocus.com, michal.hrusecky@opensuse.org, mpluskal@suse.com, mrueckert@suse.com, mseben@gmail.com, nix@opensuse.org, pth@suse.com Found By: Security Response Team Blocker: --- http://seclists.org/oss-sec/2016/q3/189 https://bugs.debian.org/832460 redis-cli stores its history in ~/.rediscli_history, this file is created with permissions 0644. Home folders are world readable as well in debian, so any user can access other users' redis history, including AUTH commands, which include credentials. I've contacted upstream on 2016-05-30 without any reaction at all and discovered this bug was first reported 3 years ago, still unfixed. @RedisLabs keeps referring to their paid support on twitter. Demo: `cat /home/*/.rediscli_history` Upstream report: https://github.com/antirez/redis/issues/3284 https://github.com/antirez/redis/pull/3322 https://github.com/antirez/redis/pull/1418 References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-7458 http://seclists.org/oss-sec/2016/q3/189 http://people.canonical.com/~ubuntu-security/cve/2013/CVE-2013-7458.html https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=832460 -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.suse.com/show_bug.cgi?id=991250 http://bugzilla.suse.com/show_bug.cgi?id=991250#c1 --- Comment #1 from Andreas Stieger <astieger@suse.com> --- https://github.com/antirez/redis/commit/9d524114eda67dedc38a9f97c9d5f3a5c374... https://github.com/antirez/redis/commit/71536684a788dc859e42132a2c5a2b737341... -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.suse.com/show_bug.cgi?id=991250 http://bugzilla.suse.com/show_bug.cgi?id=991250#c2 Andreas Stieger <astieger@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |CONFIRMED CC| |sbahling@suse.com Assignee|security-team@suse.de |mrueckert@suse.com --- Comment #2 from Andreas Stieger <astieger@suse.com> --- openSUSE:13.2:Update/redis 2.8.22 openSUSE:Backports:SLE-12/redis 3.0.7 (sbahling) openSUSE:Leap:42.1:Update/redis 3.0.4 -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=991250 https://bugzilla.suse.com/show_bug.cgi?id=991250#c11 --- Comment #11 from Swamp Workflow Management <swamp@suse.de> --- SUSE-OU-2020:3291-1: An update that solves 7 vulnerabilities, contains four features and has two fixes is now available. Category: optional (moderate) Bug References: 1002351,1047218,1061967,1064980,1097430,1131555,798455,835815,991250 CVE References: CVE-2013-7458,CVE-2015-8080,CVE-2016-10517,CVE-2016-8339,CVE-2017-15047,CVE-2018-11218,CVE-2018-11219 JIRA References: ECO-2417,ECO-2867,SLE-11578,SLE-12821 Sources used: SUSE Linux Enterprise Module for Server Applications 15-SP2 (src): redis-6.0.8-1.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. -- You are receiving this mail because: You are on the CC list for the bug.
participants (2)
-
bugzilla_noreply@novell.com
-
bugzilla_noreply@suse.com