Vulnerability Name: | CVE-2015-7529 (CCN-115087) | ||||||||||||||||
Assigned: | 2015-11-16 | ||||||||||||||||
Published: | 2015-11-16 | ||||||||||||||||
Updated: | 2023-02-13 | ||||||||||||||||
Summary: | sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$date.tar in /tmp/sosreport-$hostname-$date. | ||||||||||||||||
CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.1 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||
Vulnerability Type: | CWE-377 | ||||||||||||||||
Vulnerability Consequences: | File Manipulation | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-7529 Source: CCN Type: RHSA-2016-0152 Moderate: sos security and bug fix update Source: secalert@redhat.com Type: Third Party Advisory secalert@redhat.com Source: CCN Type: RHSA-2016-0188 Moderate: sos security and bug fix update Source: secalert@redhat.com Type: Third Party Advisory secalert@redhat.com Source: CCN Type: BID-83162 sos 2015-7529 Insecure File Permissions Vulnerability Source: secalert@redhat.com Type: Third Party Advisory, VDB Entry secalert@redhat.com Source: secalert@redhat.com Type: Issue Tracking, Third Party Advisory secalert@redhat.com Source: secalert@redhat.com Type: Issue Tracking, Third Party Advisory secalert@redhat.com Source: secalert@redhat.com Type: Issue Tracking, Third Party Advisory secalert@redhat.com Source: CCN Type: Red Hat Customer Portal CVE-2015-7529 - Red Hat Customer Portal Source: CCN Type: Red Hat Bugzilla Bug 1282542 CVE-2015-7529 sos: Usage of predictable temporary files allows privilege escalation Source: secalert@redhat.com Type: Issue Tracking, Third Party Advisory secalert@redhat.com Source: XF Type: UNKNOWN redhat-sosreport-cve20157529-symlink(115087) Source: CCN Type: sos GIT Repository A unified tool for collecting system logs and other debug information http://sos.rtfd.org Source: secalert@redhat.com Type: Issue Tracking, Patch, Third Party Advisory secalert@redhat.com | ||||||||||||||||
Vulnerable Configuration: | Configuration RedHat 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |