Executive brief
sosreport 3.2 uses weak permissions for generated sosreport archives, which allows local users with access to /var/tmp/ to obtain sensitive information by reading the contents of the archive.
Affected products
- PyPI sosreport
Junglewise Threat Intelligence
CVE-2015-3171 · Severity: low · CVSS 3.1 · Published 2017-07-25
Technologies: sosreport (PyPI). Vendors: PyPI.
sosreport 3.2 uses weak permissions for generated sosreport archives, which allows local users with access to /var/tmp/ to obtain sensitive information by reading the contents of the archive.