Description
sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$date.tar in /tmp/sosreport-$hostname-$date.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-0131 | sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$date.tar in /tmp/sosreport-$hostname-$date. |
Github GHSA |
GHSA-3g56-2hh3-35ph | SoSReport Predictable Tmp File Names |
Ubuntu USN |
USN-2845-1 | SoS vulnerabilities |
References
History
No history.
Subscriptions
Canonical
Subscribe
Ubuntu Linux
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Enterprise Linux Desktop
Subscribe
Enterprise Linux Server
Subscribe
Enterprise Linux Server Aus
Subscribe
Enterprise Linux Server Eus
Subscribe
Enterprise Linux Server Tus
Subscribe
Enterprise Linux Workstation
Subscribe
Sos Project
Subscribe
Sos
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T07:51:28.494Z
Reserved: 2015-09-29T00:00:00.000Z
Link: CVE-2015-7529
No data.
Status : Deferred
Published: 2017-11-06T17:29:00.197
Modified: 2025-04-20T01:37:25.860
Link: CVE-2015-7529
OpenCVE Enrichment
No data.
EUVD
Github GHSA
Ubuntu USN