Bugzilla – Bug 935389
VUL-1: CVE-2015-3248: openhpi: world readable /var/lib/openhpi directory
Last modified: 2015-07-01 06:19:39 UTC
via https://bugzilla.redhat.com/show_bug.cgi?id=1233520 openhpi ships with the /var/lib/openhpi/ directory set world readable and writeable. If this directory is used for storing the OPENHPI_UID_MAP or other openhpi data for exam,p[le an attacker would be able to view, modify and delete it. Even without such usage an attacker could use it to fill up the storage hosting the /var/lib/ directory if quotas are not properly set. SUSE: The directory is world readable, but NOT world writeable. So this issue does only affect us partially, although I think reading the data might not be an issue.
bugbot adjusting priority
lets considers this a non issue