CVE-2018-14650
published 2018-09-27CVE-2018-14650: It was discovered that sos-collector does not properly set the default permissions of newly created files, making all files created by the tool readable by any…
PriorityP420medium5CVSS 3.0
AVLACLPRLUIRSUCHINAN
EPSS
0.43%
34.7th percentile
It was discovered that sos-collector does not properly set the default permissions of newly created files, making all files created by the tool readable by any local user. A local attacker may use this flaw by waiting for a legit user to run sos-collector and steal the collected data in the /var/tmp directory.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| sos-collector_project | sos-collector | — | — |
CVSS provenance
nvdv3.05.0MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4pjf-x44m-95hq: It was discovered that sos-collector does not properly set the default permissions of newly created files, making all files created by the tool readab
ghsa_unreviewed·2022-05-13
CVE-2018-14650 [MEDIUM] CWE-276 GHSA-4pjf-x44m-95hq: It was discovered that sos-collector does not properly set the default permissions of newly created files, making all files created by the tool readab
It was discovered that sos-collector does not properly set the default permissions of newly created files, making all files created by the tool readable by any local user. A local attacker may use this flaw by waiting for a legit user to run sos-collector and steal the collected data in the /var/tmp directory.
Red Hat
sos-collector: incorrect permissions set on newly created files
vendor_redhat·2018-09-27·CVSS 5.9
CVE-2018-14650 [MEDIUM] CWE-276 sos-collector: incorrect permissions set on newly created files
sos-collector: incorrect permissions set on newly created files
It was discovered that sos-collector does not properly set the default permissions of newly created files, making all files created by the tool readable by any local user. A local attacker may use this flaw by waiting for a legit user to run sos-collector and steal the collected data in the /var/tmp directory.
It was discovered that sos-collector does not properly set the default permissions of newly created files, making all files created by the tool readable by any local user. A local attacker may use this flaw by waiting for a legit user to run sos-collector and steal the collected data in the /var/tmp directory.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-14650 sos-collector: incorrect permissions set on newly created files [fedora-all]
bugzilla·2018-09-27·CVSS 5.9
CVE-2018-14650 [MEDIUM] CVE-2018-14650 sos-collector: incorrect permissions set on newly created files [fedora-all]
CVE-2018-14650 sos-collector: incorrect permissions set on newly created files [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
Bugzilla
CVE-2018-14650 sos-collector: incorrect permissions set on newly created files
bugzilla·2018-09-26·CVSS 5.9
CVE-2018-14650 [MEDIUM] CVE-2018-14650 sos-collector: incorrect permissions set on newly created files
CVE-2018-14650 sos-collector: incorrect permissions set on newly created files
sos-collector does not set any permission when creating new files, thus the default umask is used, making all newly created files readable by all local users. Given the delicacy of the data collected by sos-collector, all files created by the tool, including the sos-reports collected from the cluster machines, should be accessible only the to current user. A local attacker can use this flaw to read sensitive information collected from other machines when a legit user runs sos-collector.
Upstream patch:
https://github.com/sosreport/sos-collector/commit/72058f9253e7ed8c7243e2ff76a16d97b03d65ed
Discussion:
Acknowledgments:
Name: Riccardo Schirone (Red Hat Product Security)
---
Created sos-collector tracking
https://access.redhat.com/errata/RHSA-2018:3663https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14650https://github.com/sosreport/sos-collector/commit/72058f9253e7ed8c7243e2ff76a16d97b03d65edhttps://access.redhat.com/errata/RHSA-2018:3663https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14650https://github.com/sosreport/sos-collector/commit/72058f9253e7ed8c7243e2ff76a16d97b03d65ed
2018-09-27
Published