Headline
Ubuntu Security Notice USN-5636-1
Ubuntu Security Notice 5636-1 - It was discovered that SoS incorrectly handled certain data. An attacker could possibly use this issue to expose sensitive information.
==========================================================================
Ubuntu Security Notice USN-5636-1
September 26, 2022
sosreport vulnerability
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 ESM
- Ubuntu 14.04 ESM
Summary:
SoS could be made do expose sensitive information.
Software Description:
- sosreport: Set of tools to gather troubleshooting data from a system
Details:
It was discovered that SoS incorrectly handled certain data.
An attacker could possibly use this issue to expose sensitive information.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS:
sosreport 4.3-1ubuntu2.1
Ubuntu 20.04 LTS:
sosreport 4.3-1ubuntu0.20.04.2
Ubuntu 18.04 LTS:
sosreport 4.3-1ubuntu0.18.04.2
Ubuntu 16.04 ESM:
sosreport 3.9.1-1ubuntu0.16.04.2+esm1
Ubuntu 14.04 ESM:
sosreport 3.5-1~ubuntu14.04.3+esm1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-5636-1
CVE-2022-2806
Package Information:
https://launchpad.net/ubuntu/+source/sosreport/4.3-1ubuntu2.1
https://launchpad.net/ubuntu/+source/sosreport/4.3-1ubuntu0.20.04.2
https://launchpad.net/ubuntu/+source/sosreport/4.3-1ubuntu0.18.04.2
Related news
Red Hat Security Advisory 2022-6393-01 - The ovirt-engine package provides the Red Hat Virtualization Manager, a centralized management platform that allows system administrators to view and manage virtual machines. The Manager provides a comprehensive range of features including search capabilities, resource management, live migrations, and virtual infrastructure provisioning. Issues addressed include code execution, cross site scripting, and denial of service vulnerabilities.
It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8_6, ovirt-log-collector-4.4.7-2.el8ev