|
|
Subscribe / Log in / New account

Scientific Linux alert SL-sos-20111206 (sos)

From:  riehecky@fnal.gov
To:  scientific-linux-errata@fnal.gov
Subject:  Security ERRATA Low: sos on SL6.x
Date:  Thu, 8 Dec 2011 17:12:20 -0600
Message-ID:  <201112082312.pB8NCKRu030203@fefmon2.fnal.gov>

Synopsis: Low: sos security, bug fix, and enhancement update Issue Date: 2011-12-06 CVE Numbers: CVE-2011-4083 Sos is a set of tools that gather information about system hardware and configuration. The sosreport utility incorrectly included aspects of TUV's Certificate-based private entitlement keys in the resulting archive of debugging information. An attacker able to access the archive could use the keys to access that content available to the host. This issue did not affect users of the 'Classic' access method. (CVE-2011-4083) This updated sos package also includes numerous bug fixes and enhancements. All users of sos are advised to upgrade to this updated package, which contains backported patches to correct these issues and add these enhancements. SL6: noarch sos-2.2-17.el6.noarch.rpm - Scientific Linux Development Team


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds