Bug 749383 (CVE-2011-4083) - CVE-2011-4083 sos: sosreport is gathering certificate-based RHN entitlement private keys
Summary: CVE-2011-4083 sos: sosreport is gathering certificate-based RHN entitlement p...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2011-4083
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: Unspecified
OS: Unspecified
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 750606 750607
Blocks: 742493 750605
TreeView+ depends on / blocked
 
Reported: 2011-10-26 21:20 UTC by David Kutálek
Modified: 2019-09-29 12:48 UTC (History)
10 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2012-02-21 08:19:39 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2011:1536 0 normal SHIPPED_LIVE Low: sos security, bug fix, and enhancement update 2011-12-06 01:02:03 UTC
Red Hat Product Errata RHSA-2012:0153 0 normal SHIPPED_LIVE Low: sos security, bug fix, and enhancement update 2012-02-21 07:25:08 UTC

Comment 4 Jan Lieskovsky 2011-10-27 17:28:21 UTC
The CVE identifier of CVE-2011-4083 has been assigned to this issue.

Comment 10 Jan Lieskovsky 2011-11-01 18:01:52 UTC
An information disclosure flaw was found in the way sosreport utility of the SOS, set of system support tools, retrieved debugging information for the system, intended to be compressed and sent to the technical support representative. Due to a bug in the way this debugging information was collected, the resulting archive contained not only particular Red Hat Network (RHN) entitlement certificate, but also private key for the entitlement, used to sign the certificate. A remote attacker could use this flaw to obtain unprivileged access to the content, served by this RHN entitlement.

Comment 11 Jan Lieskovsky 2011-11-01 18:03:26 UTC
This issue did NOT affect the version of the sos package, as shipped with
Red Hat Enterprise Linux 4.

--

This issue affects the versions of the sos package, as shipped with
Red Hat Enterprise Linux 5 and 6.

Comment 18 Tomas Hoger 2011-12-06 08:26:35 UTC
Lifting embargo.

Comment 19 errata-xmlrpc 2011-12-06 18:11:30 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2011:1536 https://rhn.redhat.com/errata/RHSA-2011-1536.html

Comment 23 errata-xmlrpc 2012-02-21 03:25:48 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2012:0153 https://rhn.redhat.com/errata/RHSA-2012-0153.html


Note You need to log in before you can comment on or make changes to this bug.