The sosreport utility in the Red Hat sos package before 2.2-29 does not remove the root user password information from the Kickstart configuration file (/root/anaconda-ks.cfg) when creating an archive of debugging information, which might allow attackers to obtain passwords or password hashes.
                
            References
                    Configurations
                    History
                    No history.
Information
                Published : 2012-06-29 19:55
Updated : 2017-08-29 01:31
NVD link : CVE-2012-2664
Mitre link : CVE-2012-2664
CVE.ORG link : CVE-2012-2664
JSON object : View
Products Affected
                redhat
- sos
CWE
                
                    
                        
                        CWE-255
                        
            Credentials Management Errors
