Debian Sosreport vulnerabilities
2 known vulnerabilities affecting debian/sosreport.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM1LOW1
Vulnerabilities
Page 1 of 1
CVE-2015-7529P4LOWCVSS 7.8fixed in sosreport 3.2+git276-g7da50d6-3 (bookworm)2015
CVE-2015-7529 [HIGH] CVE-2015-7529: sosreport - sosreport in SoS 3.x allows local users to obtain sensitive information from sos...
sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$date.tar in /tmp/sosreport-$hostname-$date.
Scope: local
bookworm: resolved (fixed in 3.2+git276-g7da50d6-3)
bullseye: resolved (fixed in 3.2+git276-g
debian
CVE-2015-3171P4MEDIUMCVSS 5.5fixed in sosreport 3.2-2 (bookworm)2015
CVE-2015-3171 [MEDIUM] CVE-2015-3171: sosreport - sosreport 3.2 uses weak permissions for generated sosreport archives, which allo...
sosreport 3.2 uses weak permissions for generated sosreport archives, which allows local users with access to /var/tmp/ to obtain sensitive information by reading the contents of the archive.
Scope: local
bookworm: resolved (fixed in 3.2-2)
bullseye: resolved (fixed in 3.2-2)
debian