Oval Definition:oval:com.redhat.rhsa:def:20160188
Revision Date:2016-02-16Version:639
Title:RHSA-2016:0188: sos security and bug fix update (Moderate)
Description:The sos package contains a set of utilities that gather information from system hardware, logs, and configuration files. The information can then be used for diagnostic purposes and debugging.

  • An insecure temporary file use flaw was found in the way sos created certain sosreport files. A local attacker could possibly use this flaw to perform a symbolic link attack to reveal the contents of sosreport files, or in some cases modify arbitrary files and escalate their privileges on the system. (CVE-2015-7529)

    This issue was discovered by Mateusz Guzik of Red Hat.

    This update also fixes the following bug:

  • Previously, the sosreport tool was not collecting the /var/lib/ceph and /var/run/ceph directories when run with the ceph plug-in enabled, causing the generated sosreport archive to miss vital troubleshooting information about ceph. With this update, the ceph plug-in for sosreport collects these directories, and the generated report contains more useful information. (BZ#1291347)

    All users of sos are advised to upgrade to this updated package, which contains backported patches to correct these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2015-7529
    RHSA-2016:0188
    RHSA-2016:0188-00
    RHSA-2016:0188-01
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND sos is earlier than 0:3.2-35.el7_2.3
  • AND sos is signed with Red Hat redhatrelease2 key
  • BACK