CVE-2019-13313
05.07.2019, 14:15
libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| libosinfo | libosinfo | 1.5.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux_eus | 8.1 |
| redhat | enterprise_linux_eus | 8.2 |
| redhat | enterprise_linux_eus | 8.4 |
| redhat | enterprise_linux_eus | 8.6 |
| redhat | enterprise_linux_server_aus | 8.2 |
| redhat | enterprise_linux_server_aus | 8.4 |
| redhat | enterprise_linux_server_aus | 8.6 |
| redhat | enterprise_linux_server_tus | 8.2 |
| redhat | enterprise_linux_server_tus | 8.4 |
| redhat | enterprise_linux_server_tus | 8.6 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libosinfo |
| ||||||||||||||||||||||||||||||||||||||||||||
| libosinfo-1_0-0 |
| ||||||||||||||||||||||||||||||||||||||||||||
| libosinfo-devel |
| ||||||||||||||||||||||||||||||||||||||||||||
| libosinfo-lang |
| ||||||||||||||||||||||||||||||||||||||||||||
| typelib-1_0-Libosinfo-1_0 |
|
Red Hat Enterprise Linux Releases
Common Weakness Enumeration
References