CVE-2014-3925

Severity CVSS v4.0:
Pending analysis
Type:
CWE-255 Credentials Management
Publication date:
01/06/2014
Last modified:
12/04/2025

Description

sosreport in Red Hat sos 1.7 and earlier on Red Hat Enterprise Linux (RHEL) 5 produces an archive with an fstab file potentially containing cleartext passwords, and lacks a warning about reviewing this archive to detect included passwords, which might allow remote attackers to obtain sensitive information by leveraging access to a technical-support data stream.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*
cpe:2.3:a:redhat:sos:*:*:*:*:*:*:*:* 1.7 (including)
cpe:2.3:o:redhat:enterprise_linux:5:*:*:*:*:*:*:*