187
VMScore

CVE-2015-3171

Published: 25/07/2017 Updated: 11/12/2019
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

sosreport 3.2 uses weak permissions for generated sosreport archives, which allows local users with access to /var/tmp/ to obtain sensitive information by reading the contents of the archive.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sos project sos 3.2

Vendor Advisories

Debian Bug report logs - #769521 sosreport: CVE-2015-3171: temporary file created with world-readable permissions Package: sosreport; Maintainer for sosreport is Louis Bouchard <louisbouchard@ubuntucom>; Source for sosreport is src:sosreport (PTS, buildd, popcon) Reported by: Louis Bouchard <louisbouchard@ubuntucom&gt ...
sosreport 32 uses weak permissions for generated sosreport archives, which allows local users with access to /var/tmp/ to obtain sensitive information by reading the contents of the archive ...