CVE-2019-13313

Related Vulnerabilities: CVE-2019-13313  

Impact: Low Public Date: 2019-07-05 CWE: CWE-214 Bugzilla: 1727766: CVE-2019-13313 libosinfo: information disclosure by listing process libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line.

The MITRE CVE dictionary describes this issue as:

libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line.

Find out more about CVE-2019-13313 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 3.3
CVSS3 Base Metrics CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity Impact None
Availability Impact None

Affected Packages State

Platform Package State
Red Hat Virtualization 4 libosinfo Under investigation
Red Hat Enterprise Linux 8 libsoinfo Under investigation
Red Hat Enterprise Linux 7 libsoinfo Under investigation