Vulnerabilities > CVE-2014-0246 - Credentials Management vulnerability in Sosreport Project Sosreport

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE

Summary

SOSreport stores the md5 hash of the GRUB bootloader password in an archive, which allows local users to obtain sensitive information by reading the archive.

Vulnerable Configurations

Part Description Count
Application
Sosreport_Project
1

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2014-7479.NASL
    descriptionUpdated sos packages that fix a number of bugs and add several enhancements are now available. Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-03-17
    modified2014-06-27
    plugin id76265
    published2014-06-27
    reporterThis script is Copyright (C) 2014-2020 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/76265
    titleFedora 20 : sos-3.1-1.fc20 (2014-7479)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2014-7490.NASL
    descriptionUpdated sos packages that fix a number of bugs and add several enhancements are now available. Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-03-17
    modified2014-06-27
    plugin id76266
    published2014-06-27
    reporterThis script is Copyright (C) 2014-2020 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/76266
    titleFedora 19 : sos-3.1-1.fc19 (2014-7490)