CVE-2012-2664
published 2012-06-29CVE-2012-2664: The sosreport utility in the Red Hat sos package before 2.2-29 does not remove the root user password information from the Kickstart configuration file…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.43%
70.1th percentile
The sosreport utility in the Red Hat sos package before 2.2-29 does not remove the root user password information from the Kickstart configuration file (/root/anaconda-ks.cfg) when creating an archive of debugging information, which might allow attackers to obtain passwords or password hashes.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | sos | <= 2.2-18 | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3979-2hvm-67c3: The sosreport utility in the Red Hat sos package before 2
ghsa_unreviewed·2022-05-17
CVE-2012-2664 [MEDIUM] GHSA-3979-2hvm-67c3: The sosreport utility in the Red Hat sos package before 2
The sosreport utility in the Red Hat sos package before 2.2-29 does not remove the root user password information from the Kickstart configuration file (/root/anaconda-ks.cfg) when creating an archive of debugging information, which might allow attackers to obtain passwords or password hashes.
Red Hat
sosreport does not blank root password in anaconda plugin
vendor_redhat·2012-02-14·CVSS 4.3
CVE-2012-2664 [MEDIUM] sosreport does not blank root password in anaconda plugin
sosreport does not blank root password in anaconda plugin
The sosreport utility in the Red Hat sos package before 2.2-29 does not remove the root user password information from the Kickstart configuration file (/root/anaconda-ks.cfg) when creating an archive of debugging information, which might allow attackers to obtain passwords or password hashes.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0246 sos: md5 hash of GRUB password collected when running sosreport
bugzilla·2014-05-27·CVSS 4.3
CVE-2014-0246 [MEDIUM] CVE-2014-0246 sos: md5 hash of GRUB password collected when running sosreport
CVE-2014-0246 sos: md5 hash of GRUB password collected when running sosreport
When using a GRUB bootloader password, the md5 hash of said password was collected and stored in the resulting archive of debugging information when running sosreport. An attacker able to access the archive could use this flaw to obtain the GRUB bootloader password.
Discussion:
Acknowledgements:
Red Hat would like to thank Dolev Farhi of F5 Networks for reporting this issue.
---
This issue is a similar scenario to https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-2664
---
Created sos tracking bugs for this issue:
Affects: fedora-all [bug 1101474]
---
Please see https://bugzilla.redhat.com/show_bug.cgi?id=1102633#c4 for an explanation of why this is not a security issue. The sos program cannot accoun
Bugzilla
CVE-2012-2664 sosreport does not blank root password in anaconda plugin
bugzilla·2012-05-31·CVSS 4.3
CVE-2012-2664 [MEDIUM] CVE-2012-2664 sosreport does not blank root password in anaconda plugin
CVE-2012-2664 sosreport does not blank root password in anaconda plugin
It was found that sosreport's "anaconda" plugin collects /root/anaconda-ks.cfg, which contains the root password for the system, possibly crypt'd, possibly plain.
sosreport should blank this password in a similar way to the ldap plugin's treatment of bindpw in /etc/ldap.conf
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2012:0958 https://rhn.redhat.com/errata/RHSA-2012-0958.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2013:1121 https://rhn.redhat.com/errata/RHSA-2013-1121.html
---
Statement:
(none)
http://rhn.redhat.com/errata/RHSA-2012-0958.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1121.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/54116https://exchange.xforce.ibmcloud.com/vulnerabilities/76468http://rhn.redhat.com/errata/RHSA-2012-0958.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1121.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/54116https://exchange.xforce.ibmcloud.com/vulnerabilities/76468
2012-06-29
Published