CVE-2025-0374

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 30, 2025
Updated: Feb 7, 2025
CWE ID 732

Summary

CVE-2025-0374 is a vulnerability affecting etcupdate's handling of file conflicts during system updates. When etcupdate encounters conflicts, it saves a version with conflict markers in a world-readable directory, potentially exposing encrypted root and user passwords from the temporary master.passwd file. This occurs only when conflicts arise within password files and are resolved, resulting in the deletion of the unprotected file.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share