CVE-2015-3171

MEDIUM5.5EPSS 0.04%

sosreport sensitive information disclosure via weak permissions of the generated archives

Published: 5/13/2022Modified: 4/28/2026

Description

sosreport 3.2 uses weak permissions for generated sosreport archives, which allows local users with access to /var/tmp/ to obtain sensitive information by reading the contents of the archive.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

References (7)