SCIENTIFIC-LINUX-ERRATA Archives

December 2011

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Condense Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Sender:
Security Errata for Scientific Linux <[log in to unmask]>
Subject:
From:
Pat Riehecky <[log in to unmask]>
Date:
Thu, 8 Dec 2011 17:12:20 -0600
Comments:
Reply-To:
Parts/Attachments:
text/plain (27 lines)
Synopsis:    Low: sos security, bug fix, and enhancement update
Issue Date:  2011-12-06
CVE Numbers: CVE-2011-4083


Sos is a set of tools that gather information about system hardware and
configuration.

The sosreport utility incorrectly included aspects of TUV's Certificate-based
private entitlement keys in the resulting archive of debugging
information. An attacker able to access the archive could use the keys to
access that content available to the host. This issue did not
affect users of the 'Classic' access method. (CVE-2011-4083)

This updated sos package also includes numerous bug fixes and enhancements.


All users of sos are advised to upgrade to this updated package, which
contains backported patches to correct these issues and add these
enhancements.

SL6:
  noarch
     sos-2.2-17.el6.noarch.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2