VDB
KO

PYSEC-2017-72

Details

sosreport 3.2 uses weak permissions for generated sosreport archives, which allows local users with access to /var/tmp/ to obtain sensitive information by reading the contents of the archive.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / sosreport
Introduced in: 0 Fixed in: d7759d3ddae5fe99a340c88a1d370d65cfa73fd6
Fix pip install --upgrade 'sosreport>=d7759d3ddae5fe99a340c88a1d370d65cfa73fd6'

References