First published: Tue May 05 2015(Updated: )
It was reported that sosreport creates output files with world-readable permissions: -rw-r--r--. 1 root root 7331624 May 4 08:55 sosreport-localhost.localdomain-20150504084328.tar.xz -rw-r--r--. 1 root root 33 May 4 08:55 sosreport-localhost.localdomain-20150504084328.tar.xz.md5 The archive may consists of files originally only accessible by the root user. However, after extracting the archive, all of the files are readable by regular users with access to /var/tmp/. Acknowledgements: Red Hat would like to thank Grant Murphy for reporting this issue.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sos Project Sos | =3.2 | |
pip/sosreport | <3.3 | 3.3 |
=3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.