Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-7529

Опубликовано: 01 дек. 2015
Источник: redhat
CVSS2: 6
EPSS Низкий

Описание

sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$date.tar in /tmp/sosreport-$hostname-$date.

An insecure temporary file use flaw was found in the way sos created certain sosreport files. A local attacker could possibly use this flaw to perform a symbolic link attack to reveal the contents of sosreport files, or in some cases modify arbitrary files and escalate their privileges on the system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5sosWill not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)sosWill not fix
Red Hat OpenStack Platform 8 (Liberty)sosNot affected
Red Hat Enterprise Linux 6sosFixedRHSA-2016:015209.02.2016
Red Hat Enterprise Linux 7sosFixedRHSA-2016:018816.02.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-377
https://bugzilla.redhat.com/show_bug.cgi?id=1282542sos: Usage of predictable temporary files allows privilege escalation

EPSS

Процентиль: 18%
0.00058
Низкий

6 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 8 лет назад

sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$date.tar in /tmp/sosreport-$hostname-$date.

CVSS3: 7.8
nvd
почти 8 лет назад

sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$date.tar in /tmp/sosreport-$hostname-$date.

CVSS3: 7.8
debian
почти 8 лет назад

sosreport in SoS 3.x allows local users to obtain sensitive informatio ...

CVSS3: 7.8
github
больше 3 лет назад

SoSReport Predictable Tmp File Names

oracle-oval
больше 9 лет назад

ELSA-2016-0188: sos security and bug fix update (MODERATE)

EPSS

Процентиль: 18%
0.00058
Низкий

6 Medium

CVSS2