CVE-2005-1760: High severity redhat Sysreport vulnerability
Published Jun 13, 2005
·Updated
sysreport 1.3.15 and earlier includes contents of the up2date file in a report, which leaks the password for a proxy server in plaintext and allows local users to gain privileges.
Affected Software
19 affected components
redhat Sysreport=1.2
redhat Sysreport=1.1
redhat Sysreport=1.3
redhat Enterprise Linux=2.1
redhat Enterprise Linux=4.0
redhat Enterprise Linux Desktop=3.0
redhat Linux Advanced Workstation=2.1
redhat Enterprise Linux=4.0
redhat Enterprise Linux=3.0
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Linux Advanced Workstation=2.1
redhat Enterprise Linux=4.0
redhat Enterprise Linux=3.0
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux Desktop=4.0
redhat Enterprise Linux=2.1
redhat Enterprise Linux=3.0
Remediation
Patch Available
Event History
Jun 13, 2005
CVE Published
04:00 AM
Jun 14, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1760?
CVE-2005-1760 is considered a high severity vulnerability due to the potential for local privilege escalation by exposing sensitive information.
2
How do I fix CVE-2005-1760?
To fix CVE-2005-1760, upgrade to a patched version of sysreport beyond 1.3.15.
3
Which software versions are affected by CVE-2005-1760?
CVE-2005-1760 affects Red Hat Sysreport versions 1.1 through 1.3.15 and some versions of Red Hat Enterprise Linux.
4
What type of vulnerability is CVE-2005-1760?
CVE-2005-1760 is classified as a local privilege escalation vulnerability.
5
Can CVE-2005-1760 be exploited remotely?
No, CVE-2005-1760 can only be exploited by local users on the system.