CVE-2012-2664

critical

Description

The sosreport utility in the Red Hat sos package before 2.2-29 does not remove the root user password information from the Kickstart configuration file (/root/anaconda-ks.cfg) when creating an archive of debugging information, which might allow attackers to obtain passwords or password hashes.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/76468

http://www.securityfocus.com/bid/54116

http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html

http://rhn.redhat.com/errata/RHSA-2013-1121.html

http://rhn.redhat.com/errata/RHSA-2012-0958.html

Details

Source: Mitre, NVD

Published: 2012-06-29

Updated: 2017-08-29

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical