Vulnerability CVE-2022-29869: Information
Description
cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) characters but is not a valid credentials file.
Severity: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Severity: MEDIUM (4.3)
Vector: CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:N/A:N
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
|---|---|---|---|---|---|---|
| cifs-utils | sisyphus | 6.15-alt1 | 7.3-alt1 | ALT-PU-2022-2522-1 | 306005 | Fixed |
| cifs-utils | sisyphus_e2k | 6.15-alt1 | 7.1-alt2 | ALT-PU-2022-5942-1 | - | Fixed |
| cifs-utils | sisyphus_riscv64 | 6.15-alt1 | 7.3-alt1 | ALT-PU-2022-5891-1 | - | Fixed |
| cifs-utils | p11 | 6.15-alt1 | 7.1-alt2 | ALT-PU-2022-2522-1 | 306005 | Fixed |
| cifs-utils | p10 | 6.15-alt1 | 7.1-alt1 | ALT-PU-2022-2576-1 | 306006 | Fixed |
| cifs-utils | p10_e2k | 6.15-alt1 | 7.1-alt1 | ALT-PU-2022-6096-1 | - | Fixed |
| cifs-utils | c10f2 | 6.15-alt1 | 6.15-alt1 | ALT-PU-2022-2576-1 | 306006 | Fixed |
| cifs-utils | c9f2 | 6.15-alt1 | 6.15-alt1 | ALT-PU-2022-2563-1 | 306007 | Fixed |