dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "dracut", "binary_version": "044+3-3" }, { "binary_name": "dracut-config-generic", "binary_version": "044+3-3" }, { "binary_name": "dracut-config-rescue", "binary_version": "044+3-3" }, { "binary_name": "dracut-core", "binary_version": "044+3-3" }, { "binary_name": "dracut-core-dbgsym", "binary_version": "044+3-3" }, { "binary_name": "dracut-network", "binary_version": "044+3-3" } ] }