Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2016-0152

Опубликовано: 09 фев. 2016
Источник: oracle-oval
Платформа: Oracle Linux 6

Описание

ELSA-2016-0152: sos security and bug fix update (MODERATE)

[3.2-28.0.1.2]

[= 3.2-28.el6_7.2]

  • [sosreport] Report correct final path with --build Related: bz1290953

[= 3.2-28.el6_7.1]

  • [hpasm] Add timeout. Resolves: bz1291828

[= 3.2-28.el6_7]

  • [sosreport] Prepare report in a private subdirectory Resolves: bz1290953

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

sos

3.2-28.0.1.el6_7.2

Oracle Linux i686

sos

3.2-28.0.1.el6_7.2

Oracle Linux sparc64

sos

3.2-28.0.1.el6_7.2

Связанные CVE

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 8 лет назад

sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$date.tar in /tmp/sosreport-$hostname-$date.

redhat
почти 10 лет назад

sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$date.tar in /tmp/sosreport-$hostname-$date.

CVSS3: 7.8
nvd
почти 8 лет назад

sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$date.tar in /tmp/sosreport-$hostname-$date.

CVSS3: 7.8
debian
почти 8 лет назад

sosreport in SoS 3.x allows local users to obtain sensitive informatio ...

CVSS3: 7.8
github
больше 3 лет назад

SoSReport Predictable Tmp File Names