Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 7: MGASA-2021-0325 Moderate: Libosinfo Password Exposure

mageia
Calendar Grey July 10, 2021
Dist Mageia Esm H88
Revised libosinfo updates tackle critical security vulnerabilities to safeguard confidential credential information from illicit exposure.
Updated libosinfo packages fix security vulnerability: A flaw was found in libosinfo, version 1.5.0, where the script for automated guest installations, 'osinfo-install-script', a...

Summary

Updated libosinfo packages fix security vulnerability:
A flaw was found in libosinfo, version 1.5.0, where the script for automated guest installations, 'osinfo-install-script', accepts user and admin passwords via command line arguments. This could allow guest passwords to leak to other system users via a process listing (CVE-2019-13313).
The libosinfo package has been updated to version 1.8.0, fixing this issue and other bugs.

References

- https://bugs.mageia.org/show_bug.cgi?id=25112

- https://access.redhat.com/errata/RHSA-2019:3387

- https://access.redhat.com/errata/RHBA-2020:4758

- https://www.cve.org/CVERecord?id=CVE-2019-13313

Resolution

SRPMS

- 7/core/libosinfo-1.8.0-1.mga7

Publication date: 10 Jul 2021
URL: https://advisories.mageia.org/MGASA-2021-0325.html
Type: security
CVE: CVE-2019-13313

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here