CVE-2013-6412

The transform_save function in transform.c in Augeas 1.0.0 through 1.1.0 does not properly calculate the permission values when the umask contains a "7," which causes world-writable permissions to be used for new files and allows local users to modify the files via unspecified vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.6 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 12%
VendorProductVersion
augeasaugeas
1.0.0
augeasaugeas
1.1.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
augeas
bullseye
1.12.0-2
fixed
wheezy
not-affected
squeeze
not-affected
bookworm
1.14.0-1
fixed
sid
1.14.1-1
fixed
trixie
1.14.1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
augeas
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
not-affected
saucy
ignored
raring
ignored
quantal
not-affected
precise
ignored
lucid
ignored
Common Weakness Enumeration