An updated sysreport package that fixes an information disclosure flaw is
This update has been rated as having moderate security impact by the Red
Hat Security Response Team
Sysreport is a utility that gathers information about a system's hardware
and configuration. The information can then be used for diagnostic purposes
When run by the root user, sysreport includes the contents of the
/etc/sysconfig/rhn/up2date configuration file. If up2date has been
configured to connect to a proxy server that requires an authentication
password, that password is included in plain text in the system report.
The Common Vulnerabilities and Exposures project assigned the name
CAN-2005-1760 to this issue.
Users of sysreport should update to this erratum package, which contains a
patch that removes any proxy authentication passwords.