Bug 1122781 (CVE-2014-3561) - CVE-2014-3561 ovirt-engine-log-collector: database password disclosed in process listing
Summary: CVE-2014-3561 ovirt-engine-log-collector: database password disclosed in proc...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2014-3561
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact: Petr Beňas
URL:
Whiteboard:
Depends On: 1122789 1122790
Blocks: 1122793
TreeView+ depends on / blocked
 
Reported: 2014-07-24 04:40 UTC by David Jorm
Modified: 2023-05-12 19:35 UTC (History)
19 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2014-12-03 00:01:16 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2014:1947 0 normal SHIPPED_LIVE Low: rhevm-log-collector security update 2014-12-03 01:26:37 UTC

Description David Jorm 2014-07-24 04:40:51 UTC
IssueDescription:

It was found that rhevm-log-collector called sosreport with the PostgreSQL database password passed as a command line parameter. A local attacker could read this password by monitoring a process listing. The password would also be written to a log file, which could potentially be read by a local attacker.

Comment 4 Trevor Jay 2014-09-03 00:30:16 UTC
Acknowledgements:

This issue was discovered by David Jorm of Red Hat Product Security.

Comment 7 Petr Beňas 2014-12-01 11:35:38 UTC
Both dependencies verified, setting verified.

Comment 8 errata-xmlrpc 2014-12-02 20:27:05 UTC
This issue has been addressed in the following products:

  RHEV Manager version 3.4

Via RHSA-2014:1947 https://rhn.redhat.com/errata/RHSA-2014-1947.html


Note You need to log in before you can comment on or make changes to this bug.