Vulnerability Details CVE-2013-6412
The transform_save function in transform.c in Augeas 1.0.0 through 1.1.0 does not properly calculate the permission values when the umask contains a "7," which causes world-writable permissions to be used for new files and allows local users to modify the files via unspecified vectors.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 28.7%
CVSS Severity
CVSS v2 Score 4.6
Products affected by CVE-2013-6412
-
cpe:2.3:a:augeas:augeas:1.0.0
-
cpe:2.3:a:augeas:augeas:1.1.0