Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24910
HistoryApr 10, 2020 - 1:09 a.m.

Information Disclosure

2020-04-1001:09:03
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

0.001 Low

EPSS

Percentile

40.8%

kexec-tools is vulnerable to information disclosure. mkdumprd included unneeded sensitive files (such as all files from the β€œ/root/.ssh/” directory and the host’s private SSH keys) in the resulting initrd. This could lead to an information leak when initrd files were previously created with world-readable permissions. Note: With this update, only the SSH client configuration, known hosts files, and the SSH key configured via the newly introduced sshkey option in β€œ/etc/kdump.conf” are included in the initrd. The default is the key generated when running the β€œservice kdump propagate” command, β€œ/root/.ssh/kdump_id_rsa”.