Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3g56-2hh3-35ph

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.5
CVSS3: 7.8

Описание

SoSReport Predictable Tmp File Names

sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$date.tar in /tmp/sosreport-$hostname-$date.

Пакеты

Наименование

sosreport

pip
Затронутые версииВерсия исправления

>= 3.0, < 3.3

3.3

EPSS

Процентиль: 18%
0.00058
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 8 лет назад

sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$date.tar in /tmp/sosreport-$hostname-$date.

redhat
почти 10 лет назад

sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$date.tar in /tmp/sosreport-$hostname-$date.

CVSS3: 7.8
nvd
почти 8 лет назад

sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$date.tar in /tmp/sosreport-$hostname-$date.

CVSS3: 7.8
debian
почти 8 лет назад

sosreport in SoS 3.x allows local users to obtain sensitive informatio ...

oracle-oval
больше 9 лет назад

ELSA-2016-0188: sos security and bug fix update (MODERATE)

EPSS

Процентиль: 18%
0.00058
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-59