Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Ubuntu: 5636-1 Moderate: SoSreport Sensitive Info Exposure

Ubuntu Large Esm H500
SoS could be made do expose sensitive information.
=========================================================================Ubuntu Security Notice USN-5636-1
September 26, 2022

sosreport vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 ESM
- Ubuntu 14.04 ESM

Summary:

SoS could be made do expose sensitive information.

Software Description:
- sosreport: Set of tools to gather troubleshooting data from a system

Details:

It was discovered that SoS incorrectly handled certain data.
An attacker could possibly use this issue to expose sensitive information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
  sosreport                       4.3-1ubuntu2.1

Ubuntu 20.04 LTS:
  sosreport                       4.3-1ubuntu0.20.04.2

Ubuntu 18.04 LTS:
  sosreport                       4.3-1ubuntu0.18.04.2

Ubuntu 16.04 ESM:
  sosreport                       3.9.1-1ubuntu0.16.04.2+esm1

Ubuntu 14.04 ESM:
  sosreport                       3.5-1~ubuntu14.04.3+esm1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-5636-1
  CVE-2022-2806

Package Information:
  https://launchpad.net/ubuntu/+source/sosreport/4.3-1ubuntu2.1
  https://launchpad.net/ubuntu/+source/sosreport/4.3-1ubuntu0.20.04.2
  https://launchpad.net/ubuntu/+source/sosreport/4.3-1ubuntu0.18.04.2

Ubuntu: 5636-1 Moderate: SoSreport Sensitive Info Exposure

ubuntu
Calendar Grey September 26, 2022
Dist Ubuntu Esm H88
Enhance your configuration to resolve the SoS vulnerability that may leak confidential data in Ubuntu distributions.
SoS could be made do expose sensitive information.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: sosreport 4.3-1ubuntu2.1 Ubuntu 20.04 LTS: sosreport 4.3-1ubuntu0.20.04.2 Ubuntu 18.04 LTS: sosreport 4.3-1ubuntu0.18.04.2 Ubuntu 16.04 ESM: sosreport 3.9.1-1ubuntu0.16.04.2+esm1 Ubuntu 14.04 ESM: sosreport 3.5-1~ubuntu14.04.3+esm1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5636-1

CVE-2022-2806

September 26, 2022

Package Information

https://launchpad.net/ubuntu/+source/sosreport/4.3-1ubuntu2.1 https://launchpad.net/ubuntu/+source/sosreport/4.3-1ubuntu0.20.04.2 https://launchpad.net/ubuntu/+source/sosreport/4.3-1ubuntu0.18.04.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here