An issue was discovered in FRRouting FRR (aka Free Range Routing) through 7.3.1. When using the split-config feature, the init script creates an empty config file with world-readable default permissions, leading to a possible information leak via tools/frr.in and tools/frrcommon.sh.in. NOTE: some parties consider this user error, not a vulnerability, because the permissions are under the control of the user before any sensitive information is present in the file
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T12:04:22.891Z
Reserved: 2020-05-13T00:00:00
Link: CVE-2020-12831
Updated: 2024-08-04T12:04:22.891Z
Status : Modified
Published: 2020-05-13T18:15:12.047
Modified: 2024-11-21T05:00:21.780
Link: CVE-2020-12831
OpenCVE Enrichment
No data.