CVE-2012-4453

low
Published 2012-10-09 · Modified 2026-04-29
CVSS v3
CVSS v2
2.1
VIR risk
2.1

Description

dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-4453

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://bugzilla.redhat.com/show_bug.cgi?id=859448

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed020-1.1
debian debianbullseyefixed020-1.1
debian debianforkyfixed020-1.1
debian debiansidfixed020-1.1
debian debiantrixiefixed020-1.1
fedora fedora16affected
fedora fedora17affected
redhat rhel6.0affected

Application impact

VendorProductVersionsFixed
dracut_projectdracut{"endExcluding":"024"}024

References

CWEs

CWE-276

Verify integrity in audit chain (admin only). AS-IS.