MagniComp SysInfo before 10-H81, as shipped with BMC BladeLogic Automation and other products, contains an information exposure vulnerability in which a local unprivileged user is able to read any root (uid 0) owned file on the system, regardless of the file permissions. Confidential information such as password hashes (/etc/shadow) or other secrets (such as log files or private keys) can be leaked to the attacker. The vulnerability has a confidentiality impact, but has no direct impact on system integrity or availability.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://sintonen.fi/advisories/magnicomp-sysinfo-information-exposure.txt | third party advisory |
http://www.securityfocus.com/archive/1/542024/100/0/threaded | mailing list |
http://packetstormsecurity.com/files/147687/MagniComp-SysInfo-Information-Exposure.html | vdb entry third party advisory |