dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "044+3-3", "binary_name": "dracut" }, { "binary_version": "044+3-3", "binary_name": "dracut-config-generic" }, { "binary_version": "044+3-3", "binary_name": "dracut-config-rescue" }, { "binary_version": "044+3-3", "binary_name": "dracut-core" }, { "binary_version": "044+3-3", "binary_name": "dracut-core-dbgsym" }, { "binary_version": "044+3-3", "binary_name": "dracut-network" } ] }