CVE-2014-4040
Publication date 17 June 2014
Last updated 24 July 2024
Ubuntu priority
Description
snap in powerpc-utils 1.2.20 produces an archive with fstab and yaboot.conf files potentially containing cleartext passwords, and lacks a warning about reviewing this archive to detect included passwords, which might allow remote attackers to obtain sensitive information by leveraging access to a technical-support data stream.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| powerpc-utils | 16.04 LTS xenial |
Not affected
|
| 14.04 LTS trusty | Not in release | |
| ppc64-diag | 16.04 LTS xenial |
Not affected
|
| 14.04 LTS trusty | Not in release | |
Notes
sbeattie
snap script is in powerpc-utils (powerpc-ibm-utils binary package), which ppc64diag depends on. code is not present in powerpc-utils 1.1.3.