Candidate: CVE-2019-13313 PublicDate: 2019-07-05 14:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13313 https://gitlab.com/libosinfo/libosinfo/-/tags https://gitlab.com/libosinfo/libosinfo/blob/master/NEWS https://libosinfo.org/download/ https://www.redhat.com/archives/libosinfo/2019-July/msg00026.html Description: libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_libosinfo: upstream_libosinfo: needs-triage precise/esm_libosinfo: DNE trusty_libosinfo: ignored (out of standard support) trusty/esm_libosinfo: DNE xenial_libosinfo: ignored (end of standard support, was needs-triage) bionic_libosinfo: needs-triage cosmic_libosinfo: ignored (reached end-of-life) disco_libosinfo: ignored (reached end-of-life) eoan_libosinfo: not-affected (1.6.0-1) focal_libosinfo: not-affected (1.6.0-1) groovy_libosinfo: not-affected (1.6.0-1) hirsute_libosinfo: not-affected (1.6.0-1) impish_libosinfo: not-affected (1.6.0-1) jammy_libosinfo: not-affected (1.6.0-1) devel_libosinfo: not-affected (1.6.0-1)