Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3925

Опубликовано: 29 мая 2014
Источник: redhat
CVSS2: 1.9
EPSS Низкий

Описание

sosreport in Red Hat sos 1.7 and earlier on Red Hat Enterprise Linux (RHEL) 5 produces an archive with an fstab file potentially containing cleartext passwords, and lacks a warning about reviewing this archive to detect included passwords, which might allow remote attackers to obtain sensitive information by leveraging access to a technical-support data stream.

Отчет

This issue did not affect the versions of sosreport as shipped with Red Hat Enterprise Linux 6.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6sosNot affected
Red Hat Enterprise Linux 5sosFixedRHBA-2014:120016.09.2014

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=1103324sos: does not indicate data sent is potentially sensitive on Red Hat Enterprise Linux 5

EPSS

Процентиль: 80%
0.02152
Низкий

1.9 Low

CVSS2

Связанные уязвимости

ubuntu
около 12 лет назад

sosreport in Red Hat sos 1.7 and earlier on Red Hat Enterprise Linux (RHEL) 5 produces an archive with an fstab file potentially containing cleartext passwords, and lacks a warning about reviewing this archive to detect included passwords, which might allow remote attackers to obtain sensitive information by leveraging access to a technical-support data stream.

nvd
около 12 лет назад

sosreport in Red Hat sos 1.7 and earlier on Red Hat Enterprise Linux (RHEL) 5 produces an archive with an fstab file potentially containing cleartext passwords, and lacks a warning about reviewing this archive to detect included passwords, which might allow remote attackers to obtain sensitive information by leveraging access to a technical-support data stream.

debian
около 12 лет назад

sosreport in Red Hat sos 1.7 and earlier on Red Hat Enterprise Linux ( ...

github
около 4 лет назад

sosreport in Red Hat sos 1.7 and earlier on Red Hat Enterprise Linux (RHEL) 5 produces an archive with an fstab file potentially containing cleartext passwords, and lacks a warning about reviewing this archive to detect included passwords, which might allow remote attackers to obtain sensitive information by leveraging access to a technical-support data stream.

EPSS

Процентиль: 80%
0.02152
Низкий

1.9 Low

CVSS2