Oval Definition:oval:com.redhat.rhsa:def:20050502
Revision Date:2005-06-13Version:502
Title:RHSA-2005:502: sysreport security update (Moderate)
Description:Sysreport is a utility that gathers information about a system's hardware and configuration. The information can then be used for diagnostic purposes and debugging.

When run by the root user, sysreport includes the contents of the /etc/sysconfig/rhn/up2date configuration file. If up2date has been configured to connect to a proxy server that requires an authentication password, that password is included in plain text in the system report. The Common Vulnerabilities and Exposures project assigned the name CAN-2005-1760 to this issue.

Users of sysreport should update to this erratum package, which contains a patch that removes any proxy authentication passwords.
Family:unixClass:patch
Status:Reference(s):CVE-2005-1760
RHSA-2005:502-01
Platform(s):Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 4
Product(s):
Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 3 is installed
  • AND sysreport is earlier than 0:1.3.7.2-6
  • AND sysreport is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND sysreport is earlier than 0:1.3.15-2
  • AND sysreport is signed with Red Hat master key
  • BACK