René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

165 lines
5.5 KiB
JSON

{
"id": "CVE-2011-4083",
"sourceIdentifier": "secalert@redhat.com",
"published": "2014-02-17T16:55:07.273",
"lastModified": "2014-02-19T00:40:38.407",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "The sosreport utility in the Red Hat sos package before 1.7-9 and 2.x before 2.2-17 includes (1) Certificate-based Red Hat Network private entitlement keys and the (2) private key for the entitlement in an archive of debugging information, which might allow remote attackers to obtain sensitive information by reading the archive."
},
{
"lang": "es",
"value": "La utilidad sosreport en el paquete sos de Red Hat anterior a 1.7-9 y 2.x anterior a 2.2-17 incluye (1) claves de derechos privadas basadas en certificado de Red Hat Network y la (2) clave privada para el derecho en un archivo con informaci\u00f3n de depuraci\u00f3n, lo que podr\u00eda permitir a atacantes remotos obtener informaci\u00f3n sensible mediante la lectura del archivo."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 4.3
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-310"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:redhat:sos:2.2-3:*:*:*:*:*:*:*",
"matchCriteriaId": "22EEE016-AAA4-44D5-B82C-211E306D6A06"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:redhat:sos:2.2-6:*:*:*:*:*:*:*",
"matchCriteriaId": "5B7125C6-7DB3-4447-B66D-2A863C7C758E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:redhat:sos:2.2-7:*:*:*:*:*:*:*",
"matchCriteriaId": "72EC1F77-E9DF-4162-8F1A-28DBF21CC52B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:redhat:sos:2.2-8:*:*:*:*:*:*:*",
"matchCriteriaId": "7C0C2C21-5770-4D48-A1D8-D2DEBF1652F7"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:redhat:sos:2.2-9:*:*:*:*:*:*:*",
"matchCriteriaId": "9B85DFD1-2903-43DF-B811-830E439EBA81"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:redhat:sos:2.2-10:*:*:*:*:*:*:*",
"matchCriteriaId": "1FA0FF67-39A6-4E01-B092-55EFC9AEA446"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:redhat:sos:2.2-11:*:*:*:*:*:*:*",
"matchCriteriaId": "41B4DA50-0086-4253-8EFE-F290961BB7A4"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:redhat:sos:2.2-14:*:*:*:*:*:*:*",
"matchCriteriaId": "1ABC0B4D-E429-46BB-BA58-8A6AD3A3EF46"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:redhat:sos:2.2-15:*:*:*:*:*:*:*",
"matchCriteriaId": "67213CE4-E23B-4499-94DC-7CDFC6C5B4E4"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:redhat:sos:2.2-16:*:*:*:*:*:*:*",
"matchCriteriaId": "E69CE230-0E4C-4BC7-BE83-F5AF3F97DE2B"
}
]
}
]
},
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:redhat:sos:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.7-6",
"matchCriteriaId": "861BFDE5-0104-4922-B542-B8DFE9E99EBB"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:redhat:sos:1.6:*:*:*:*:*:*:*",
"matchCriteriaId": "CB09510B-26F9-4B0B-872E-D114BD4645F2"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:redhat:sos:1.7:*:*:*:*:*:*:*",
"matchCriteriaId": "A5231190-05A6-4FDF-B298-585F86D15348"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:redhat:sos:1.7-8:*:*:*:*:*:*:*",
"matchCriteriaId": "8F3460E1-4C40-4405-9E04-9FAC0409E69F"
}
]
}
]
}
],
"references": [
{
"url": "http://rhn.redhat.com/errata/RHSA-2011-1536.html",
"source": "secalert@redhat.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2012-0153.html",
"source": "secalert@redhat.com",
"tags": [
"Vendor Advisory"
]
}
]
}