CVE-2014-3561: Infoleak
The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listing the processes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3561?
CVE-2014-3561 is classified as a moderate severity vulnerability due to the exposure of sensitive database password information.
How do I fix CVE-2014-3561?
To fix CVE-2014-3561, update to the latest version of the rhevm-log-collector package from Red Hat that addresses this issue.
Who is affected by CVE-2014-3561?
CVE-2014-3561 affects users of Red Hat Enterprise Virtualization 3.4 who have access to the command line.
What is the impact of CVE-2014-3561?
The impact of CVE-2014-3561 allows local users to potentially gain access to sensitive PostgreSQL database passwords.
Is there a workaround for CVE-2014-3561?
A potential workaround for CVE-2014-3561 is to restrict access to the sosreport command to trusted users only.