Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Tue, 5 Jan 2016 11:13:46 +0100
From: Salvatore Bonaccorso <>
To: OSS Security Mailinglist <>
Subject: CVE Request: netfilter-persistent: (local) information leak due to
 world-readable rules files


iptables-persistent (in Debian) is a loader for netfilter configuration
using a plugin-based architecture.

iptables-persistent is vulnerable to a (local) information leak due to
world-readable rules files. It was reported in Debian in

And fixed via

Could you assign a CVE for this issue?

p.s.: There is a fork of iptables-persistent. But I have not checked
if the fork is as well
affected by this issue).


Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ