This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-16200 | In some cases, Kea log files or lease files may be world-readable. This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8. |
Solution
Upgrade to the patched release most closely related to your current version of Kea: 2.4.2, 2.6.3, or 2.7.9.
Workaround
It is possible to work around this problem by ensuring that the directories that contain the logs and lease files are only accessible to trusted users.
Tue, 17 Jun 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| CPEs | cpe:/o:redhat:enterprise_linux:10.0 | |
| Vendors & Products |
Redhat
Redhat enterprise Linux |
Fri, 30 May 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-538 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 28 May 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 28 May 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In some cases, Kea log files or lease files may be world-readable. This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8. | |
| Title | Insecure file permissions can result in confidential information leakage | |
| Weaknesses | CWE-276 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: isc
Published:
Updated: 2025-05-28T17:28:58.513Z
Reserved: 2025-04-10T12:51:45.056Z
Link: CVE-2025-32803
Updated: 2025-05-28T17:28:50.413Z
Status : Awaiting Analysis
Published: 2025-05-28T18:15:27.130
Modified: 2025-05-29T14:29:50.247
Link: CVE-2025-32803
OpenCVE Enrichment
No data.
EUVD