SoSReport Predictable Tmp File Names
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Oct 27, 2024
Description
Published by the National Vulnerability Database
Nov 6, 2017
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Aug 2, 2023
Last updated
Oct 27, 2024
sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by
sosreport-$hostname-$date.tar
in/tmp/sosreport-$hostname-$date
.References