2 results (0.003 seconds)

CVSS: 2.1EPSS: 0%CPEs: 1EXPL: 0

sysreport before 1.3.7 allows local users to obtain sensitive information via a symlink attack on a temporary directory. • http://secunia.com/advisories/16381 http://secunia.com/advisories/17539 http://securitytracker.com/id?1014653 http://www.osvdb.org/18682 http://www.redhat.com/archives/fedora-announce-list/2005-November/msg00034.html http://www.redhat.com/archives/fedora-announce-list/2005-November/msg00035.html http://www.redhat.com/support/errata/RHSA-2005-598.html http://www.securityfocus.com/bid/15379 https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=162978 https://exchange.xforce.ibmcloud •

CVSS: 7.5EPSS: 0%CPEs: 19EXPL: 0

sysreport 1.3.15 and earlier includes contents of the up2date file in a report, which leaks the password for a proxy server in plaintext and allows local users to gain privileges. • http://secunia.com/advisories/15675 http://securitytracker.com/id?1014181 http://www.redhat.com/support/errata/RHSA-2005-502.html http://www.securityfocus.com/bid/13936 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A623 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9522 https://access.redhat.com/security/cve/CVE-2005-1760 https://bugzilla.redhat.com/show_bug.cgi?id=1617664 •