First published: Fri Sep 21 2012(Updated: )
An information disclosure flaw was found in the way dracut, an initramfs root filesystem images generator, created initramfs images. When the root filesystem contained sensitive information (password based authentication for iSCSI systems or encrypted root filesystem crypttab password information), an attacker could use this flaw to obtain this information. Acknowledgements: This issue was discovered by Peter Jones of the Red Hat Installer Team.
Affected Software | Affected Version | How to fix |
---|---|---|
Dracut |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-859448 is considered to be high due to the potential for sensitive information disclosure.
To fix REDHAT-BUG-859448, update the dracut package to the latest version provided by Red Hat, addressing the information disclosure flaw.
REDHAT-BUG-859448 can lead to the exposure of sensitive information stored in the initramfs images, impacting system security.
Yes, your data may be at risk due to the potential exposure of sensitive credentials and configurations through REDHAT-BUG-859448.
REDHAT-BUG-859448 affects multiple versions of dracut; check your installed version against Red Hat's advisories for specifics.