Bug 917904 - (CVE-2013-1815) CVE-2013-1815 OpenStack packstack: answerfile creation permissions issue
CVE-2013-1815 OpenStack packstack: answerfile creation permissions issue
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
: Security
Depends On: 917905
Blocks: 917906
  Show dependency treegraph
Reported: 2013-03-05 00:03 EST by Kurt Seifried
Modified: 2016-04-26 10:30 EDT (History)
10 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2013-04-08 13:53:35 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Kurt Seifried 2013-03-05 00:03:59 EST
Derek Higgins (derekh@redhat.com) of Red Hat reports:

packstack creates a answerfile containing configuration details for an 
openstack deployment. But after a recent comment in 
https://bugzilla.redhat.com/show_bug.cgi?id=906410 [Open URL] comment 4, I 
reviewed the code on how it is generated.

The file was being opened, written to and then the mode was being changed to 


def generateAnswerFile(outputFile, overrides={}):
    sep = os.linesep
    fmt = ("%(comment)s%(separator)s%(conf_name)s=%(default_value)s"
    outputFile = os.path.expanduser(outputFile)
    with open(outputFile, "w") as ans_file:
    os.chmod(outputFile, 0600)

and the answer path is provided by:

def _getanswerfilepath():
    path = None
    msg = "Could not find a suitable path on which to create the answerfile"

    # We'll use the first path with
    # write permissions. Order matters.
    for p in ["./", "~/", "/tmp"]:
        if os.access(p, os.W_OK):
            path = os.path.abspath(

The current directory "./" may be accessible to an attacker, and "/tmp" is 
definitely accessible to attackers. The file permissions should also be set
securely prior to placing the information in it.
Comment 2 Derek Higgins 2013-03-05 04:24:54 EST
Fix merged upstream 
Comment 3 Murray McAllister 2013-03-19 00:50:43 EDT

This issue was discovered by Derek Higgins of the Red Hat OpenStack team.
Comment 4 errata-xmlrpc 2013-03-21 14:24:25 EDT
This issue has been addressed in following products:

  OpenStack Folsom for RHEL 6

Via RHSA-2013:0671 https://rhn.redhat.com/errata/RHSA-2013-0671.html

Note You need to log in before you can comment on or make changes to this bug.