SCIENTIFIC-LINUX-ERRATA Archives

March 2012

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Patrick Riehecky <[log in to unmask]>
Reply To:
Date:
Wed, 21 Mar 2012 16:25:11 -0500
Content-Type:
text/plain
Parts/Attachments:
text/plain (25 lines)
Synopsis:    Low: sos security, bug fix, and enhancement update
Issue Date:  2012-02-21
CVE Numbers: CVE-2011-4083


Sos is a set of tools that gather information about system hardware and
configuration.

The sosreport utility incorrectly included Certificate-based private
entitlement keys for upstream updates in the resulting archive of debugging
information. An attacker able to access the archive could use the keys to
access content available to the host. Scientific Linux systems
cannot use this upstream service and are unaffected. (CVE-2011-4083)

This updated sos package also includes numerous bug fixes and enhancements.

All sos users are advised to upgrade to this updated package, which
resolves these issues and adds these enhancements.

SL5:
  noarch
     sos-1.7-9.62.el5.noarch.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2