PT-2017-6652 · Openhpi+2 · Openhpi+2
CVSS v3.1
4.7
Média
| Vetor | AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OpenHPI versions prior to 3.6.0
Description
The issue allows local users to cause a denial of service due to disk consumption by filling the filesystem hosting /var/lib. This is possible because the /var/lib/openhpi directory has world-writable permissions. A local user could use this flaw to view, modify, and delete OpenHPI-related data, or fill up the storage device hosting the /var/lib directory.
Recommendations
For versions prior to 3.6.0, update to version 3.6.0 or later to resolve the issue. As a temporary workaround, consider restricting write access to the /var/lib/openhpi directory to prevent unauthorized modifications and minimize the risk of disk consumption.
Correção
DoS
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Centos
Openhpi
Red Hat