CVE-2019-13313
Description
RHSA-2019:3387: osinfo-db and libosinfo security and bug fix update (Low)
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
Description Libosinfo: osinfo-install-script option leaks password via command line argument CVSS v3: 2.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 7libosinfo-0:1.1.0-5.el7RHSA-2020:10512020-03-31T00:00:00Z Red Hat Enterprise Linux 8gnome-boxes-0:3.28.5-7.el8RHSA-2019:33872019-11-05T00:00:00Z Red Hat Enterpriseβ¦
Description
Libosinfo: osinfo-install-script option leaks password via command line argument
CVSS v3: 2.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N)
Errata / fixed releases
| Product | Package | Advisory | Released |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | libosinfo-0:1.1.0-5.el7 | RHSA-2020:1051 | 2020-03-31T00:00:00Z |
| Red Hat Enterprise Linux 8 | gnome-boxes-0:3.28.5-7.el8 | RHSA-2019:3387 | 2019-11-05T00:00:00Z |
| Red Hat Enterprise Linux 8 | libosinfo-0:1.5.0-3.el8 | RHSA-2019:3387 | 2019-11-05T00:00:00Z |
| Red Hat Enterprise Linux 8 | osinfo-db-0:20190611-1.el8 | RHSA-2019:3387 | 2019-11-05T00:00:00Z |
| Red Hat Enterprise Linux 8 | osinfo-db-tools-0:1.5.0-4.el8 | RHSA-2019:3387 | 2019-11-05T00:00:00Z |
Apply commands
yum update -y libosinfo
# or:
dnf upgrade -y libosinfo
OS impact
SUSE Affected 1 release
| Version | Status | Fixed in |
|---|---|---|
| β | Affected | β |
Debian Fixed 5 releases
| Version | Status | Fixed in |
|---|---|---|
| trixie | Fixed | 1.6.0-1 |
| sid | Fixed | 1.6.0-1 |
| forky | Fixed | 1.6.0-1 |
| bullseye | Fixed | 1.6.0-1 |
| bookworm | Fixed | 1.6.0-1 |
Red Hat Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| 8 | Fixed | β |
References
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.