Vulnerabilities > CVE-2014-3925 - Credentials Management vulnerability in multiple products

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
canonical
redhat
CWE-255
nessus

Summary

sosreport in Red Hat sos 1.7 and earlier on Red Hat Enterprise Linux (RHEL) 5 produces an archive with an fstab file potentially containing cleartext passwords, and lacks a warning about reviewing this archive to detect included passwords, which might allow remote attackers to obtain sensitive information by leveraging access to a technical-support data stream.

Common Weakness Enumeration (CWE)

Nessus

NASL familyUbuntu Local Security Checks
NASL idUBUNTU_USN-2845-1.NASL
descriptionDolev Farhi discovered an information disclosure issue in SoS. If the /etc/fstab file contained passwords, the passwords were included in the SoS report. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-3925) Mateusz Guzik discovered that SoS incorrectly handled temporary files. A local attacker could possibly use this issue to overwrite arbitrary files or gain access to temporary file contents containing sensitive system information. (CVE-2015-7529). Note that Tenable Network Security has extracted the preceding description block directly from the Ubuntu security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
last seen2020-06-01
modified2020-06-02
plugin id87499
published2015-12-18
reporterUbuntu Security Notice (C) 2015-2019 Canonical, Inc. / NASL script (C) 2015-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/87499
titleUbuntu 14.04 LTS / 15.04 / 15.10 : sosreport vulnerabilities (USN-2845-1)

Redhat

advisories
bugzilla
id1107751
titlebackport fstab and grub.conf password stripping from upstream
oval
OR
  • commentRed Hat Enterprise Linux must be installed
    ovaloval:com.redhat.rhba:tst:20070304026
  • AND
    • commentRed Hat Enterprise Linux 5 is installed
      ovaloval:com.redhat.rhba:tst:20070331005
    • commentsos is earlier than 0:1.7-9.73.el5
      ovaloval:com.redhat.rhba:tst:20141200001
    • commentsos is signed with Red Hat redhatrelease key
      ovaloval:com.redhat.rhba:tst:20141200002
rhsa
idRHBA-2014:1200
released2014-09-16
severityNone
titleRHBA-2014:1200: sos bug fix update (None)
rpmssos-0:1.7-9.73.el5