REDHAT-BUG-1727766: Low severity libosinfo-l10n vulnerability
libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line.
Reference: https://gitlab.com/libosinfo/libosinfo/-/tags https://gitlab.com/libosinfo/libosinfo/blob/master/NEWS https://libosinfo.org/download/ https://www.redhat.com/archives/libosinfo/2019-July/msg00026.html
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1727766?
The severity of REDHAT-BUG-1727766 is considered to be moderate due to the exposure of sensitive credentials.
How do I fix REDHAT-BUG-1727766?
To fix REDHAT-BUG-1727766, you should upgrade to the latest version of libosinfo that addresses this vulnerability.
Which versions of libosinfo are affected by REDHAT-BUG-1727766?
libosinfo versions prior to 1.5.0 are affected by REDHAT-BUG-1727766.
Can REDHAT-BUG-1727766 be exploited remotely?
No, REDHAT-BUG-1727766 requires local access to exploit the vulnerability.
What types of credentials are exposed in REDHAT-BUG-1727766?
The vulnerability in REDHAT-BUG-1727766 exposes user credentials that are passed via the command line to the osinfo-install-script.