—
PYSEC-2017-72
Details
sosreport 3.2 uses weak permissions for generated sosreport archives, which allows local users with access to /var/tmp/ to obtain sensitive information by reading the contents of the archive.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI / sosreport
Introduced in:
0 Fixed in: d7759d3ddae5fe99a340c88a1d370d65cfa73fd6 Fix
pip install --upgrade 'sosreport>=d7759d3ddae5fe99a340c88a1d370d65cfa73fd6'