Red Hat Bugzilla – Bug 826884
CVE-2012-2664 sosreport does not blank root password in anaconda plugin
Last modified: 2013-10-03 22:31:56 EDT
It was found that sosreport's "anaconda" plugin collects /root/anaconda-ks.cfg, which contains the root password for the system, possibly crypt'd, possibly plain. sosreport should blank this password in a similar way to the ldap plugin's treatment of bindpw in /etc/ldap.conf
This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2012:0958 https://rhn.redhat.com/errata/RHSA-2012-0958.html
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2013:1121 https://rhn.redhat.com/errata/RHSA-2013-1121.html
Statement: (none)