Security
Headlines
HeadlinesLatestCVEs

Headline

Ubuntu Security Notice USN-5636-1

Ubuntu Security Notice 5636-1 - It was discovered that SoS incorrectly handled certain data. An attacker could possibly use this issue to expose sensitive information.

Packet Storm
#vulnerability#ubuntu

==========================================================================
Ubuntu Security Notice USN-5636-1
September 26, 2022

sosreport vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS
  • Ubuntu 18.04 LTS
  • Ubuntu 16.04 ESM
  • Ubuntu 14.04 ESM

Summary:

SoS could be made do expose sensitive information.

Software Description:

  • sosreport: Set of tools to gather troubleshooting data from a system

Details:

It was discovered that SoS incorrectly handled certain data.
An attacker could possibly use this issue to expose sensitive information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
sosreport 4.3-1ubuntu2.1

Ubuntu 20.04 LTS:
sosreport 4.3-1ubuntu0.20.04.2

Ubuntu 18.04 LTS:
sosreport 4.3-1ubuntu0.18.04.2

Ubuntu 16.04 ESM:
sosreport 3.9.1-1ubuntu0.16.04.2+esm1

Ubuntu 14.04 ESM:
sosreport 3.5-1~ubuntu14.04.3+esm1

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5636-1
CVE-2022-2806

Package Information:
https://launchpad.net/ubuntu/+source/sosreport/4.3-1ubuntu2.1
https://launchpad.net/ubuntu/+source/sosreport/4.3-1ubuntu0.20.04.2
https://launchpad.net/ubuntu/+source/sosreport/4.3-1ubuntu0.18.04.2

Related news

Red Hat Security Advisory 2022-6393-01

Red Hat Security Advisory 2022-6393-01 - The ovirt-engine package provides the Red Hat Virtualization Manager, a centralized management platform that allows system administrators to view and manage virtual machines. The Manager provides a comprehensive range of features including search capabilities, resource management, live migrations, and virtual infrastructure provisioning. Issues addressed include code execution, cross site scripting, and denial of service vulnerabilities.

CVE-2022-2806: [ovirt] answer files: Filter out all password keys by didib · Pull Request #2947 · sosreport/sos

It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8_6, ovirt-log-collector-4.4.7-2.el8ev

Packet Storm: Latest News

Falco 0.39.1