Sysreport is a utility that gathers information about a system’s hardware
and configuration. The information can then be used for diagnostic purposes
and debugging.
When run by the root user, sysreport includes the contents of the
/etc/sysconfig/rhn/up2date configuration file. If up2date has been
configured to connect to a proxy server that requires an authentication
password, that password is included in plain text in the system report.
The Common Vulnerabilities and Exposures project assigned the name
CAN-2005-1760 to this issue.
Users of sysreport should update to this erratum package, which contains a
patch that removes any proxy authentication passwords.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
RedHat | any | noarch | sysreport | < 1.3.15-2 | sysreport-1.3.15-2.noarch.rpm |
RedHat | any | noarch | sysreport | < 1.3.7.2-6 | sysreport-1.3.7.2-6.noarch.rpm |
RedHat | any | noarch | sysreport | < 1.3.7.0-4 | sysreport-1.3.7.0-4.noarch.rpm |