CVE-2017-15131

It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy. This only affects xdg-user-dirs before 0.15.5 as shipped with Red Hat Enterprise Linux.
Configurations

Configuration 1 (hide)

cpe:2.3:a:freedesktop:xdg-user-dirs:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*

History

12 Feb 2023, 23:28

Type Values Removed Values Added
CWE CWE-276 CWE-284
Summary It was found that the system umask policy is not being honored when creating XDG user directories (~/Desktop etc) on first login. This could lead to user's files being inadvertently exposed to other local users. It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy. This only affects xdg-user-dirs before 0.15.5 as shipped with Red Hat Enterprise Linux.
References
  • {'url': 'https://access.redhat.com/security/cve/CVE-2017-15131', 'name': 'https://access.redhat.com/security/cve/CVE-2017-15131', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=1455094', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=1455094', 'tags': [], 'refsource': 'MISC'}

02 Feb 2023, 15:17

Type Values Removed Values Added
CWE CWE-284 CWE-276
References
  • {'url': 'https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E', 'name': '[mina-dev] 20210225 [jira] [Created] (FTPSERVER-500) Security vulnerability in common/lib/log4j-1.2.17.jar', 'tags': [], 'refsource': 'MLIST'}
  • (MISC) https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E -
  • (MISC) https://access.redhat.com/security/cve/CVE-2017-15131 -
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1455094 -
Summary It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy. This only affects xdg-user-dirs before 0.15.5 as shipped with Red Hat Enterprise Linux. It was found that the system umask policy is not being honored when creating XDG user directories (~/Desktop etc) on first login. This could lead to user's files being inadvertently exposed to other local users.

25 Feb 2021, 17:15

Type Values Removed Values Added
References
  • (MLIST) https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E -
CWE CWE-276 CWE-284

Information

Published : 2018-01-09 21:29

Updated : 2023-12-10 12:15


NVD link : CVE-2017-15131

Mitre link : CVE-2017-15131

CVE.ORG link : CVE-2017-15131


JSON object : View

Products Affected

freedesktop

  • xdg-user-dirs

redhat

  • enterprise_linux
CWE
CWE-284

Improper Access Control

CWE-276

Incorrect Default Permissions