>> Redhat Security Update Fixes Sysreport Information Disclosure Issue
Title : Redhat Security Update Fixes Sysreport Information Disclosure Issue VUPEN ID : VUPEN/ADV-2005-0760 CVE ID : CVE-2005-1760 CWE ID : CWE-
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-06-14
Technical Description
Redhat has released a security patch to correct a vulnerability identified in Sysreport. When run by the root user, sysreport includes the contents of the "/etc/sysconfig/rhn/up2date" configuration file. If up2date has been configured to connect to a proxy server that requires an authentication password, that password is included in plain text in the system report.