Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-2150

Опубликовано: 23 июл. 2015
Источник: redhat
CVSS2: 1.2

Описание

xfs_metadump in xfsprogs before 3.2.4 does not properly obfuscate file data, which allows remote attackers to obtain sensitive information by reading a generated image.

It was discovered that the xfs_metadump tool of the xfsprogs suite did not fully adhere to the standards of obfuscation described in its man page. In case a user with the necessary privileges used xfs_metadump and relied on the advertised obfuscation, the generated data could contain unexpected traces of potentially sensitive information.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5xfsprogsWill not fix
Red Hat Enterprise Linux 6xfsprogsWill not fix
Red Hat Enterprise Linux 7xfsprogsFixedRHSA-2015:215119.11.2015

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=817696xfsprogs: xfs_metadump information disclosure flaw

1.2 Low

CVSS2

Связанные уязвимости

ubuntu
около 10 лет назад

xfs_metadump in xfsprogs before 3.2.4 does not properly obfuscate file data, which allows remote attackers to obtain sensitive information by reading a generated image.

nvd
около 10 лет назад

xfs_metadump in xfsprogs before 3.2.4 does not properly obfuscate file data, which allows remote attackers to obtain sensitive information by reading a generated image.

debian
около 10 лет назад

xfs_metadump in xfsprogs before 3.2.4 does not properly obfuscate file ...

suse-cvrf
больше 9 лет назад

Security update for xfsprogs

suse-cvrf
больше 9 лет назад

Security update for xfsprogs

1.2 Low

CVSS2