SCIENTIFIC-LINUX-ERRATA Archives

February 2016

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Tue, 16 Feb 2016 16:26:16 +0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (28 lines)
Synopsis:          Moderate: sos security and bug fix update
Advisory ID:       SLSA-2016:0188-1
Issue Date:        2016-02-16
CVE Numbers:       CVE-2015-7529
--

An insecure temporary file use flaw was found in the way sos created
certain sosreport files. A local attacker could possibly use this flaw to
perform a symbolic link attack to reveal the contents of sosreport files,
or in some cases modify arbitrary files and escalate their privileges on
the system. (CVE-2015-7529)

This update also fixes the following bug:

* Previously, the sosreport tool was not collecting the /var/lib/ceph and
/var/run/ceph directories when run with the ceph plug-in enabled, causing
the generated sosreport archive to miss vital troubleshooting information
about ceph. With this update, the ceph plug-in for sosreport collects
these directories, and the generated report contains more useful
information.
--

SL7
  noarch
    sos-3.2-35.el7_2.3.noarch.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2