Wind River Support Network

HomeDefectsLIN8-5619
Fixed

LIN8-5619 : Security Advisory - hostapd - CVE-2012-2389

Created: Jan 19, 2017    Updated: Dec 3, 2018
Resolved Date: Jan 19, 2017
Previous ID: LIN7-7362
Found In Version: 8.0.0.13
Fix Version: 8.0.0.14
Severity: Low
Applicable for: Wind River Linux 8
Component/s: Userspace

Description

hostapd 0.7.3, and possibly other versions before 1.0, uses 0644 permissions for /etc/hostapd/hostapd.conf, which might allow local users to obtain sensitive information such as credentials.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2389

Steps to Reproduce

$ /lpg-build/cdc/sustaining/WR43RCPL26-lx03/wrlinux-4/wrlinux/../ldat/configure --enable-board=common_pc_64 --enable-rootfs=glibc_cgl --enable-kernel=cgl --enable-test=yes --enable-prebuilt-tools=no --with-product-dir=/lpg-build/cdc/sustaining/WR43RCPL26-lx03/wrlinux-4/wrlinux
$ make fs

Other Downloads


Live chat
Online