Vulnerabilities > Dracut Project

DATE CVE VULNERABILITY TITLE RISK
2018-08-01 CVE-2016-8637 Incorrect Permission Assignment for Critical Resource vulnerability in Dracut Project Dracut
A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio' is used, such as when including microcode updates.
local
low complexity
dracut-project CWE-732
7.8
2010-12-07 CVE-2010-4176 Incorrect Default Permissions vulnerability in multiple products
plymouth-pretrigger.sh in dracut and udev, when running on Fedora 13 and 14, sets weak permissions for the /dev/systty device file, which allows remote authenticated users to read terminal data from tty0 for local users.
network
low complexity
udev-project dracut-project CWE-276
4.0