CVE-2012-2664

Severity CVSS v4.0:
Pending analysis
Type:
CWE-255 Credentials Management
Publication date:
29/06/2012
Last modified:
11/04/2025

Description

The sosreport utility in the Red Hat sos package before 2.2-29 does not remove the root user password information from the Kickstart configuration file (/root/anaconda-ks.cfg) when creating an archive of debugging information, which might allow attackers to obtain passwords or password hashes.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:sos:*:*:*:*:*:*:*:* 2.2-18 (including)