OESA-2024-1077
Dashboard / Vulnerabilities / OESA-2024-1077
Summary: rear security update
Details: Relax-and-Recover is a setup-and-forget Linux bare metal disaster recovery solution. It is easy to set up and requires no maintenance so there is no excuse for not using it. Security Fix(es): Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.(CVE-2024-23301)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2024-1077, https://nvd.nist.gov/vuln/detail/CVE-2024-23301
Affected packages
Package
Name: rear
Purl: pkg:rpm/openEuler/rear&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -2.4-5.oe1
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
