Back

MEDIUM

sos: does not indicate data sent is potentially sensitive on Red Hat Enterprise Linux 5

Published Jun 1, 2014

Description

sosreport in Red Hat sos 1.7 and earlier on Red Hat Enterprise Linux (RHEL) 5 produces an archive with an fstab file potentially containing cleartext passwords, and lacks a warning about reviewing this archive to detect included passwords, which might allow remote attackers to obtain sensitive information by leveraging access to a technical-support data stream.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of sosreport as shipped with Red Hat Enterprise Linux 6.

Metrics

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 1, 2014
Updated Aug 6, 2024
Reserved May 30, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date May 29, 2014